An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-7927 An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T20:35:20.399Z

Reserved: 2017-11-09T00:00:00

Link: CVE-2017-16743

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-12T20:29:00.387

Modified: 2024-11-21T03:16:53.180

Link: CVE-2017-16743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.