HIGH · 8.8

CVE-2022-22509

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

Vulnerability Description

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PhoenixcontactFl Switch 2005 Firmware3.00
PhoenixcontactFl Switch 2005-
PhoenixcontactFl Switch 2008 Firmware3.00
PhoenixcontactFl Switch 2008-
PhoenixcontactFl Switch 2008F Firmware3.00
PhoenixcontactFl Switch 2008F-
PhoenixcontactFl Switch 2016 Firmware3.00
PhoenixcontactFl Switch 2016-
PhoenixcontactFl Switch 2105 Firmware3.00
PhoenixcontactFl Switch 2105-
PhoenixcontactFl Switch 2108 Firmware3.00
PhoenixcontactFl Switch 2108-
PhoenixcontactFl Switch 2116 Firmware3.00
PhoenixcontactFl Switch 2116-
PhoenixcontactFl Switch 2204-2Tc-2Sfx Firmware3.00
PhoenixcontactFl Switch 2204-2Tc-2Sfx-
PhoenixcontactFl Switch 2206-2Fx Firmware3.00
PhoenixcontactFl Switch 2206-2Fx-
PhoenixcontactFl Switch 2206-2Fx Sm Firmware3.00
PhoenixcontactFl Switch 2206-2Fx Sm-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22509?

CVE-2022-22509 is a vulnerability with a CVSS score of 8.8 (HIGH). In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

How severe is CVE-2022-22509?

CVE-2022-22509 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22509?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Fl Switch 2005 Firmware, Phoenixcontact Fl Switch 2005, Phoenixcontact Fl Switch 2008 Firmware, Phoenixcontact Fl Switch 2008, Phoenixcontact Fl Switch 2008F Firmware.