In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-27655 In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
Fixes

Solution

Upgrade to firmware 3.10 or higher


Workaround

Disable login via SSH on devices running firmware 3.00

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-17T01:31:08.892Z

Reserved: 2022-01-03T00:00:00

Link: CVE-2022-22509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-02T13:15:08.407

Modified: 2024-11-21T06:46:55.010

Link: CVE-2022-22509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.