Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33540


In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.


Published

2021-06-25T19:15:09.697

Last Modified

2024-11-21T06:09:02.727

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact axl_f_bk_pn_tps_xc_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_pn_tps_xc - No
Operating System phoenixcontact axl_f_bk_pn_tps_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_pn_tps - No
Operating System phoenixcontact axl_f_bk_eip_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_eip - No
Operating System phoenixcontact axl_f_bk_eip_ef_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_eip_ef - No
Operating System phoenixcontact axl_f_bk_eth_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_eth - No
Operating System phoenixcontact axl_f_bk_eth_xc_firmware < 1.30 Yes
Hardware phoenixcontact axl_f_bk_eth_xc - No
Operating System phoenixcontact axl_f_bk_s35_firmware < 1.40 Yes
Hardware phoenixcontact axl_f_bk_s35 - No
Operating System phoenixcontact axl_f_bk_pn_firmware * Yes
Hardware phoenixcontact axl_f_bk_pn - No
Operating System phoenixcontact axl_f_bk_pn_xc_firmware * Yes
Hardware phoenixcontact axl_f_bk_pn_xc - No
Operating System phoenixcontact axl_f_bk_eth_net2_firmware * Yes
Hardware phoenixcontact axl_f_bk_eth_net2 - No
Operating System phoenixcontact axl_f_bk_sas_firmware * Yes
Hardware phoenixcontact axl_f_bk_sas - No
Operating System phoenixcontact il_pn_bk-pac_firmware * Yes
Hardware phoenixcontact il_pn_bk-pac - No
Operating System phoenixcontact il_pn_bk_di8_do4_2tx-pac_firmware * Yes
Hardware phoenixcontact il_pn_bk_di8_do4_2tx-pac - No
Operating System phoenixcontact il_pn_bk_di8_do4_2scrj-pac_firmware * Yes
Hardware phoenixcontact il_pn_bk_di8_do4_2scrj-pac - No
Operating System phoenixcontact il_eth_bk_di8_do4_2tx-xc-pac_firmware * Yes
Hardware phoenixcontact il_eth_bk_di8_do4_2tx-xc-pac - No
Operating System phoenixcontact il_eth_bk_di8_do4_2tx-pac_firmware * Yes
Hardware phoenixcontact il_eth_bk_di8_do4_2tx-pac - No
Operating System phoenixcontact il_eip_bk_di8_do4_2tx-pac_firmware * Yes
Hardware phoenixcontact il_eip_bk_di8_do4_2tx-pac - No
Operating System phoenixcontact il_s3_bk_di8_do4_2tx-pac_firmware * Yes
Hardware phoenixcontact il_s3_bk_di8_do4_2tx-pac - No

References