VulnerabilityModified
CVE-2021-21003
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services.
MEDIUM 5.3EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- phoenixcontact/fl switch smcs 16tx firmware · phoenixcontact/fl switch smcs 14tx\/2fx firmware · phoenixcontact/fl switch smcs 14tx\/2fx-sm firmware · phoenixcontact/fl switch smcs 8gt firmware · phoenixcontact/fl switch smcs 6gt\/2sfp firmware · phoenixcontact/fl switch smcs 8tx-pn firmware · phoenixcontact/fl switch smcs 4tx-pn firmware · phoenixcontact/fl switch smcs 8tx firmware · phoenixcontact/fl switch smcs 6tx\/2sfp firmware · phoenixcontact/fl switch smn 6tx\/2pof-pn firmware · phoenixcontact/fl switch smn 8tx-pn firmware · phoenixcontact/fl switch smn 6tx\/2fx firmware · phoenixcontact/fl switch smn 6tx\/2fx sm firmware · phoenixcontact/fl nat smn 8tx firmware · phoenixcontact/fl nat smn 8tx-m firmware
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en-us/advisories/vde-2021-023Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-023Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.