Zurück zur Übersicht

PHOENIX CONTACT: FL SWITCH 2xxx series incorrect privilege assignment

VDE-2022-001
Last update
14.05.2025 15:00
Published at
25.01.2022 09:05
Vendor(s)
Phoenix Contact GmbH & Co. KG
External ID
VDE-2022-001
CSAF Document

Summary

The user management of the FL SWITCH 2xxx family of devices implements access rights based on roles and permission groups. An unprivileged user logged in via the SSH CLI is assigned to the admin role independent of his configured access role enabling full access to the device configuration (CWE-266 - Incorrect Privilege Assignment).

User Management via SSH was first introduced with firmware version 3.00. Firmware versions other than 3.00 are not affected by this vulnerability.

Impact

An attacker could elevate his privileges and take over control of the device.

Affected Product(s)

Model no. Product name Affected versions
2702323 FL SWITCH 2005 Firmware 3.00
2702324 FL SWITCH 2008 Firmware 3.00
1106707 FL SWITCH 2008F Firmware 3.00
2702903 FL SWITCH 2016 Firmware 3.00
2702665 FL SWITCH 2105 Firmware 3.00
2702666 FL SWITCH 2108 Firmware 3.00
2702908 FL SWITCH 2116 Firmware 3.00
2702334 FL SWITCH 2204-2TC-2SFX Firmware 3.00
2702330 FL SWITCH 2206-2FX Firmware 3.00
2702331 FL SWITCH 2206-2FX SM Firmware 3.00
2702333 FL SWITCH 2206-2FX SM ST Firmware 3.00
2702332 FL SWITCH 2206-2FX ST Firmware 3.00
2702969 FL SWITCH 2206-2SFX Firmware 3.00
1044028 FL SWITCH 2206-2SFX PN Firmware 3.00
1095628 FL SWITCH 2206C-2FX Firmware 3.00
2702328 FL SWITCH 2207-FX Firmware 3.00
2702329 FL SWITCH 2207-FX SM Firmware 3.00
2702326, 2702327 FL SWITCH 2208 Firmware 3.00
1044024 FL SWITCH 2208 PN Firmware 3.00
1095627 FL SWITCH 2208C Firmware 3.00
2702907 FL SWITCH 2212-2TC-2SFX Firmware 3.00
2702905 FL SWITCH 2214-2FX Firmware 3.00
2702906 FL SWITCH 2214-2FX SM Firmware 3.00
1006188 FL SWITCH 2214-2SFX Firmware 3.00
1044030 FL SWITCH 2214-2SFX PN Firmware 3.00
2702904 FL SWITCH 2216 Firmware 3.00
1044029 FL SWITCH 2216 PN Firmware 3.00
2702653 FL SWITCH 2304-2GC-2SFP Firmware 3.00
2702970 FL SWITCH 2306-2SFP Firmware 3.00
1009222 FL SWITCH 2306-2SFP PN Firmware 3.00
2702652 FL SWITCH 2308 Firmware 3.00
1009220 FL SWITCH 2308 PN Firmware 3.00
2702910 FL SWITCH 2312-2GC-2SFP Firmware 3.00
1006191 FL SWITCH 2314-2SFP Firmware 3.00
1031683 FL SWITCH 2314-2SFP PN Firmware 3.00
2702909 FL SWITCH 2316 Firmware 3.00
1031673 FL SWITCH 2316 PN Firmware 3.00
1184084 FL SWITCH 2316/K1 Firmware 3.00
1088853 FL SWITCH 2404-2TC-2SFX Firmware 3.00
1043414 FL SWITCH 2406-2SFX Firmware 3.00
1089126 FL SWITCH 2406-2SFX PN Firmware 3.00
1043412 FL SWITCH 2408 Firmware 3.00
1089133 FL SWITCH 2408 PN Firmware 3.00
1088875 FL SWITCH 2412-2TC-2SFX Firmware 3.00
1043423 FL SWITCH 2414-2SFX Firmware 3.00
1089139 FL SWITCH 2414-2SFX PN Firmware 3.00
1043416 FL SWITCH 2416 Firmware 3.00
1089150 FL SWITCH 2416 PN Firmware 3.00
1088872 FL SWITCH 2504-2GC-2SFP Firmware 3.00
1043491 FL SWITCH 2506-2SFP Firmware 3.00
1089135 FL SWITCH 2506-2SFP PN Firmware 3.00
1215329 FL SWITCH 2506-2SFP/K1 Firmware 3.00
1043484 FL SWITCH 2508 Firmware 3.00
1089134 FL SWITCH 2508 PN Firmware 3.00
1215350 FL SWITCH 2508/K1 Firmware 3.00
1088856 FL SWITCH 2512-2GC-2SFP Firmware 3.00
1043499 FL SWITCH 2514-2SFP Firmware 3.00
1089154 FL SWITCH 2514-2SFP PN Firmware 3.00
1043496 FL SWITCH 2516 Firmware 3.00
1089205 FL SWITCH 2516 PN Firmware 3.00
1106500 FL SWITCH 2608 Firmware 3.00
1106616 FL SWITCH 2608 PN Firmware 3.00
1106615 FL SWITCH 2708 Firmware 3.00
1106610 FL SWITCH 2708 PN Firmware 3.00

Vulnerabilities

Expand / Collapse all

Published
22.09.2025 14:58
Weakness
Improper Privilege Management (CWE-269)
Summary

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

References

Mitigation

We recommend disabling the login via SSH on devices running firmware version 3.00. If access to the CLI is required and an encrypted connection is not necessary in the specific application, the unencrypted Telnet service may be utilized, which is not affected by this vulnerability.

Remediation

Phoenix Contact strongly recommends affected users to upgrade to the current Firmware 3.10 or higher which fixes this vulnerability.

Revision History

Version Date Summary
1 25.01.2022 09:05 Initial revision.
2 14.05.2025 15:00 Fix: added distribution