SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22509

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

HIGH 8.8EPSS 0.99%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
phoenixcontact/fl switch 2005 firmware · phoenixcontact/fl switch 2008 firmware · phoenixcontact/fl switch 2008f firmware · phoenixcontact/fl switch 2016 firmware · phoenixcontact/fl switch 2105 firmware · phoenixcontact/fl switch 2108 firmware · phoenixcontact/fl switch 2116 firmware · phoenixcontact/fl switch 2204-2tc-2sfx firmware · phoenixcontact/fl switch 2206-2fx firmware · phoenixcontact/fl switch 2206-2fx sm firmware · phoenixcontact/fl switch 2206-2fx sm st firmware · phoenixcontact/fl switch 2206-2fx st firmware · phoenixcontact/fl switch 2206-2sfx firmware · phoenixcontact/fl switch 2206-2sfx pn firmware · phoenixcontact/fl switch 2206c-2fx firmware · phoenixcontact/fl switch 2207-fx firmware · phoenixcontact/fl switch 2207-fx sm firmware · phoenixcontact/fl switch 2208 firmware · phoenixcontact/fl switch 2208c firmware · phoenixcontact/fl switch 2208 pn firmware · +40 more
Source
info@cert.vde.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.