Share: Email | Twitter

ID

VDE-2022-001

Published

2022-01-25 09:05 (CET)

Last update

2022-01-25 09:05 (CET)

Vendor(s)

PHOENIX CONTACT GmbH & Co. KG

Product(s)

Article No° Product Name Affected Version(s)
2702323 FL SWITCH 2005 = 3.00
2702324 FL SWITCH 2008 = 3.00
1106707 FL SWITCH 2008F = 3.00
2702903 FL SWITCH 2016 = 3.00
2702665 FL SWITCH 2105 = 3.00
2702666 FL SWITCH 2108 = 3.00
2702908 FL SWITCH 2116 = 3.00
2702334 FL SWITCH 2204-2TC-2SFX = 3.00
2702330 FL SWITCH 2206-2FX = 3.00
2702331 FL SWITCH 2206-2FX SM = 3.00
2702333 FL SWITCH 2206-2FX SM ST = 3.00
2702332 FL SWITCH 2206-2FX ST = 3.00
2702969 FL SWITCH 2206-2SFX = 3.00
1044028 FL SWITCH 2206-2SFX PN = 3.00
1095628 FL SWITCH 2206C-2FX = 3.00
2702328 FL SWITCH 2207-FX = 3.00
2702329 FL SWITCH 2207-FX SM = 3.00
2702326 FL SWITCH 2208 = 3.00
2702327 FL SWITCH 2208 = 3.00
1095627 FL SWITCH 2208C = 3.00
1044024 FL SWITCH 2208 PN = 3.00
2702907 FL SWITCH 2212-2TC-2SFX = 3.00
2702905 FL SWITCH 2214-2FX = 3.00
2702906 FL SWITCH 2214-2FX SM = 3.00
1006188 FL SWITCH 2214-2SFX = 3.00
1044030 FL SWITCH 2214-2SFX PN = 3.00
2702904 FL SWITCH 2216 = 3.00
1044029 FL SWITCH 2216 PN = 3.00
2702653 FL SWITCH 2304-2GC-2SFP = 3.00
2702970 FL SWITCH 2306-2SFP = 3.00
1009222 FL SWITCH 2306-2SFP PN = 3.00
2702652 FL SWITCH 2308 = 3.00
1009220 FL SWITCH 2308 PN = 3.00
2702910 FL SWITCH 2312-2GC-2SFP = 3.00
1006191 FL SWITCH 2314-2SFP = 3.00
1031683 FL SWITCH 2314-2SFP PN = 3.00
2702909 FL SWITCH 2316 = 3.00
1184084 FL SWITCH 2316/K1 = 3.00
1031673 FL SWITCH 2316 PN = 3.00
1088853 FL SWITCH 2404-2TC-2SFX = 3.00
1043414 FL SWITCH 2406-2SFX = 3.00
1089126 FL SWITCH 2406-2SFX PN = 3.00
1043412 FL SWITCH 2408 = 3.00
1089133 FL SWITCH 2408 PN = 3.00
1088875 FL SWITCH 2412-2TC-2SFX = 3.00
1043423 FL SWITCH 2414-2SFX = 3.00
1089139 FL SWITCH 2414-2SFX PN = 3.00
1043416 FL SWITCH 2416 = 3.00
1089150 FL SWITCH 2416 PN = 3.00
1088872 FL SWITCH 2504-2GC-2SFP = 3.00
1043491 FL SWITCH 2506-2SFP = 3.00
1215329 FL SWITCH 2506-2SFP/K1 = 3.00
1089135 FL SWITCH 2506-2SFP PN = 3.00
1043484 FL SWITCH 2508 = 3.00
1215350 FL SWITCH 2508/K1 = 3.00
1089134 FL SWITCH 2508 PN = 3.00
1088856 FL SWITCH 2512-2GC-2SFP = 3.00
1043499 FL SWITCH 2514-2SFP = 3.00
1089154 FL SWITCH 2514-2SFP PN = 3.00
1043496 FL SWITCH 2516 = 3.00
1089205 FL SWITCH 2516 PN = 3.00
1106500 FL SWITCH 2608 = 3.00
1106616 FL SWITCH 2608 PN = 3.00
1106615 FL SWITCH 2708 = 3.00
1106610 FL SWITCH 2708 PN = 3.00

Summary

The user management of the FL SWITCH 2xxx family of devices implements access rights based on roles and permission groups. An unprivileged user logged in via the SSH CLI is assigned to the admin role independent of his configured access role enabling full access to the device configuration (CWE-266 - Incorrect Privilege Assignment).

User Management via SSH was first introduced with firmware version 3.00. Firmware versions other than 3.00 are not affected by this vulnerability.


Last Update:

17. November 2022 11:18

Weakness

Improper Privilege Management  (CWE-269) 

Summary

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

Solution

Upgrade to firmware 3.10 or higher

Reported by

This vulnerability was discovered internally.


Impact

An attacker could elevate his privileges and take over control of the device.

Solution

Mitigation

We recommend disabling the login via SSH on devices running firmware version 3.00. If access to the CLI is required and an encrypted connection is not necessary in the specific application, the unencrypted Telnet service may be utilized, which is not affected by this vulnerability.

Remediation

Phoenix Contact strongly recommends affected users to upgrade to the current Firmware 3.10 or higher which fixes this vulnerability.

Reported by

This vulnerability was discovered internally.

PHOENIX CONTACT thanks CERT@VDE for the coordination and support with this publication.