HIGH · 7.3

CVE-2021-33540

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

Vulnerability Description

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

CVSS Score

7.3

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
PhoenixcontactAxl F Bk Pn Tps Xc Firmware< 1.30
PhoenixcontactAxl F Bk Pn Tps Xc-
PhoenixcontactAxl F Bk Pn Tps Firmware< 1.30
PhoenixcontactAxl F Bk Pn Tps-
PhoenixcontactAxl F Bk Eip Firmware< 1.30
PhoenixcontactAxl F Bk Eip-
PhoenixcontactAxl F Bk Eip Ef Firmware< 1.30
PhoenixcontactAxl F Bk Eip Ef-
PhoenixcontactAxl F Bk Eth Firmware< 1.30
PhoenixcontactAxl F Bk Eth-
PhoenixcontactAxl F Bk Eth Xc Firmware< 1.30
PhoenixcontactAxl F Bk Eth Xc-
PhoenixcontactAxl F Bk S35 Firmware< 1.40
PhoenixcontactAxl F Bk S35-
PhoenixcontactAxl F Bk Pn FirmwareAll versions
PhoenixcontactAxl F Bk Pn-
PhoenixcontactAxl F Bk Pn Xc FirmwareAll versions
PhoenixcontactAxl F Bk Pn Xc-
PhoenixcontactAxl F Bk Eth Net2 FirmwareAll versions
PhoenixcontactAxl F Bk Eth Net2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33540?

CVE-2021-33540 is a vulnerability with a CVSS score of 7.3 (HIGH). In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

How severe is CVE-2021-33540?

CVE-2021-33540 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-33540?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Axl F Bk Pn Tps Xc Firmware, Phoenixcontact Axl F Bk Pn Tps Xc, Phoenixcontact Axl F Bk Pn Tps Firmware, Phoenixcontact Axl F Bk Pn Tps, Phoenixcontact Axl F Bk Eip Firmware.