CVE-2021-33540
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD
Description
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
Affected (18)
Products: Phoenixcontact: Axl F Bk Pn Tps Xc Firmware, Axl F Bk Pn Tps Firmware, Axl F Bk Eip Firmware, Axl F Bk Eip Ef Firmware, Axl F Bk Eth Firmware, Axl F Bk Eth Xc Firmware, Axl F Bk S35 Firmware, Axl F Bk Pn Firmware, Axl F Bk Pn Xc Firmware, Axl F Bk Eth Net2 Firmware, Axl F Bk Sas Firmware, Il Pn Bk Pac Firmware, Il Pn Bk Di8 Do4 2tx Pac Firmware, Il Pn Bk Di8 Do4 2scrj Pac Firmware, Il Eth Bk Di8 Do4 2tx Xc Pac Firmware, Il Eth Bk Di8 Do4 2tx Pac Firmware, Il Eip Bk Di8 Do4 2tx Pac Firmware, Il S3 Bk Di8 Do4 2tx Pac Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Pn Tps Xc | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Pn Tps | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Eip | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Eip Ef | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Eth | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Eth Xc | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.40 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk S35 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Pn | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Pn Xc | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Eth Net2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axl F Bk Sas | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Pn Bk Pac | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Pn Bk Di8 Do4 2tx Pac | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Pn Bk Di8 Do4 2scrj Pac | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Eth Bk Di8 Do4 2tx Xc Pac | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Eth Bk Di8 Do4 2tx Pac | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il Eip Bk Di8 Do4 2tx Pac | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Il S3 Bk Di8 Do4 2tx Pac | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.