CVE-2021-33540

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
25/06/2021
Last modified:
02/07/2021

Description

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:phoenixcontact:axl_f_bk_pn_tps_xc_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_pn_tps_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_pn_tps_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_pn_tps:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_eip_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_eip:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_eip_ef_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_eip_ef:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_eth_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_eth:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_eth_xc_firmware:*:*:*:*:*:*:*:* 1.30 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_eth_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_s35_firmware:*:*:*:*:*:*:*:* 1.40 (excluding)
cpe:2.3:h:phoenixcontact:axl_f_bk_s35:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axl_f_bk_pn_firmware:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools