All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://cert.vde.com/de-de/advisories/vde-2018-005 | third party advisory patch |
https://ics-cert.us-cert.gov/advisories/ICSA-18-137-02 | us government resource third party advisory patch |
http://www.securityfocus.com/bid/104231 | vdb entry third party advisory |