ZeroHour

CVE-2022-22509

CVSS 3.1
8.8 high
EPSS
<1%p60
Published
()
Modified
Description

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

Vendors
phoenixcontact
Products
fl switch 2005 firmware, fl switch 2008 firmware, fl switch 2008f firmware, fl switch 2016 firmware, fl switch 2105 firmware, fl switch 2108 firmware, fl switch 2116 firmware, fl switch 2204-2tc-2sfx firmware, fl switch 2206-2fx firmware, fl switch 2206-2fx sm firmware, fl switch 2206-2fx sm st firmware, fl switch 2206-2fx st firmware
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.