SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21004

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

MEDIUM 6.1EPSS 0.58%

Does this matter?

Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.

Description

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.58% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
phoenixcontact/fl switch smcs 16tx firmware · phoenixcontact/fl switch smcs 14tx\/2fx firmware · phoenixcontact/fl switch smcs 14tx\/2fx-sm firmware · phoenixcontact/fl switch smcs 8gt firmware · phoenixcontact/fl switch smcs 6gt\/2sfp firmware · phoenixcontact/fl switch smcs 8tx-pn firmware · phoenixcontact/fl switch smcs 4tx-pn firmware · phoenixcontact/fl switch smcs 8tx firmware · phoenixcontact/fl switch smcs 6tx\/2sfp firmware · phoenixcontact/fl switch smn 6tx\/2pof-pn firmware · phoenixcontact/fl switch smn 8tx-pn firmware · phoenixcontact/fl switch smn 6tx\/2fx firmware · phoenixcontact/fl switch smn 6tx\/2fx sm firmware · phoenixcontact/fl nat smn 8tx firmware · phoenixcontact/fl nat smn 8tx-m firmware
Source
info@cert.vde.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.