CVE-2017-16743

UnknownEPSS 3.11%

Last modified

CVE-2017-16743 is a vulnerability of currently unknown severity. An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.. EPSS estimates a 3.11% chance of exploitation in the next 30 days.

Description

An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.

Metrics

EPSS Probability
3.11%

86.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhoenixcontactFl Switch 3005 Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3005t Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3004t-Fx Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3004t-Fx St Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3008 Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3008t Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3006t-2fx Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3006t-2fx St Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3012e-2sfx Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3016e Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3016 Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3016t Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3006t-2fx Sm Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4008t-2sfp Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4008t-2gt-4fx Sm Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4008t-2gt-3fx Sm Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx Lc-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx Sm-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx Sm St-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx St-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4808e-16fx Sm Lc-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4012t 2gt 2fx Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4012t-2gt-2fx St Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4824e-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4800e-24fx-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4800e-24fx Sm-4gc Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 3012e-2fx Sm Firmware>= 1.0, <= 1.32
PhoenixcontactFl Switch 4000t-8poe-2sfp-R Firmware>= 1.0, <= 1.32

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-16743?
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
How severe is CVE-2017-16743?
Severity scoring for CVE-2017-16743 is pending analysis. The EPSS model estimates a 3.11% probability of exploitation in the next 30 days.
How do I fix CVE-2017-16743?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-16743?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST