7.5
CVSSv3

CVE-2021-21005

Published: 25/06/2021 Updated: 01/07/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact fl_switch_smcs_16tx_firmware

phoenixcontact fl_switch_smcs_14tx\\/2fx_firmware

phoenixcontact fl_switch_smcs_14tx\\/2fx-sm_firmware

phoenixcontact fl_switch_smcs_8gt_firmware

phoenixcontact fl_switch_smcs_6gt\\/2sfp_firmware

phoenixcontact fl_switch_smcs_8tx-pn_firmware

phoenixcontact fl_switch_smcs_4tx-pn_firmware

phoenixcontact fl_switch_smcs_8tx_firmware

phoenixcontact fl_switch_smcs_6tx\\/2sfp_firmware

phoenixcontact fl_switch_smn_6tx\\/2pof-pn_firmware

phoenixcontact fl_switch_smn_8tx-pn_firmware

phoenixcontact fl_switch_smn_6tx\\/2fx_firmware

phoenixcontact fl_switch_smn_6tx\\/2fx_sm_firmware

phoenixcontact fl_nat_smn_8tx_firmware

phoenixcontact fl_nat_smn_8tx-m_firmware