Unknown
CVE-2017-16743
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
CVE-2017-16743
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- fl switch 3004t-fx firmware,
- fl switch 3004t-fx st firmware,
- fl switch 3005 firmware,
- fl switch 3005t firmware,
- fl switch 3006t-2fx firmware,
- fl switch 3006t-2fx sm firmware,
- fl switch 3006t-2fx st firmware,
- fl switch 3008 firmware,
- fl switch 3008t firmware,
- fl switch 3012e-2fx sm firmware,
- fl switch 3012e-2sfx firmware,
- fl switch 3016 firmware,
- fl switch 3016e firmware,
- fl switch 3016t firmware,
- fl switch 4000t-8poe-2sfp-r firmware,
- fl switch 4008t-2gt-3fx sm firmware,
- fl switch 4008t-2gt-4fx sm firmware,
- fl switch 4008t-2sfp firmware,
- fl switch 4012t 2gt 2fx firmware,
- fl switch 4012t-2gt-2fx st firmware,
- fl switch 4800e-24fx sm-4gc firmware,
- fl switch 4800e-24fx-4gc firmware,
- fl switch 4808e-16fx lc-4gc firmware,
- fl switch 4808e-16fx sm lc-4gc firmware,
- fl switch 4808e-16fx sm st-4gc firmware,
- fl switch 4808e-16fx sm-4gc firmware,
- fl switch 4808e-16fx st-4gc firmware,
- fl switch 4808e-16fx-4gc firmware,
- fl switch 4824e-4gc firmware
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: