Share: Email | Twitter

ID

VDE-2021-022

Published

2021-06-23 14:16 (CEST)

Last update

2021-07-07 13:17 (CEST)

Vendor(s)

PHOENIX CONTACT

Product(s)

Product number Product name Firmware version
2313452 FL COMSERVER UNI 232/422/485 < 2.40
2904817 FL COMSERVER UNI 232/422/485-T < 2.40

Summary

When the communication partner sends an invalid Modbus exception response to the FL COMSERVER UNI as a query, the Modbus communication stops, and the device will be unresponsive for some minutes before the functionality is fully restored (CWE-772).


Weakness

Missing Release of Resource after Effective Lifetime  ( CWE-772 ) 

Summary

In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.

Impact

An attacker may use this vulnerability to execute a Denial of Service (DoS) attack.

Solution

PHOENIX CONTACT recommends affected users to upgrade to the latest firmware version which is available for download.

Product number Product name Firmware version
2313452 FL COMSERVER UNI 232/422/485 2.41
2904817 FL COMSERVER UNI 232/422/485-T 2.41

Reported by

This vulnerability was found by Petri Tuomio and reported to PHOENIX CONTACT by Waertsilae PSIRT.
We kindly appreciate the coordinated disclosure of this vulnerability by the finder.
PHOENIX CONTACT thanks CERT@VDE for the coordination and support with this publication.