Vulnerabilities > CVE-2021-21005 - Unspecified vulnerability in Phoenixcontact products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
phoenixcontact

Summary

In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

Vulnerable Configurations

Part Description Count
OS
Phoenixcontact
30
Hardware
Phoenixcontact
15