« Volver al listado

CVE-2017-16723

Estado: ModificadaMedia (6.1)—

A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (13)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-16723",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "PHOENIX CONTACT FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH",
          "versions": [
            {
              "status": "affected",
              "version": "PHOENIX CONTACT FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-11T16:29:00.283",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/102111",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://cert.vde.com/de-de/advisories/vde-2017-004",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-341-03",
      "tags": [
        "Issue Tracking",
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/102111",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert.vde.com/de-de/advisories/vde-2017-004",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-341-03",
      "tags": [
        "Issue Tracking",
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de Cross-Site Scripting en PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485 y PSI-MODEM/ETH (ejecutando firmware en versiones anteriores a la 1.99, 2.20 o 2.40). La vulnerabilidad de Cross-Site Scripting (XSS) se ha identificado, la cual podría permitir la ejecución remota de código."
    }
  ],
  "lastModified": "2026-06-17T01:09:42.913",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_basic_232_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "081CA4C1-545F-426B-A940-E2CD8B129739"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_basic_232:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A788C822-BAAE-4B34-89F0-0BAFCAB657EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_uni_422_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43F7F87F-6848-4D96-BB43-79506C77BE2C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_uni_422:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AEF623AA-5DA9-46B1-AEF1-47DDEC848257"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_bas_485-t_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFB35907-990C-4A93-8D7C-FBAA264C0CC2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_bas_485-t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BC84DA94-5FAE-4481-96DA-968F7C5B06FD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_com_server_rs232_firmware:1.99:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D452E08-C6CD-4F2A-85B5-23C985F38CCB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_com_server_rs232:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8CA5C995-B9B7-40CE-A144-E00C12579601"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_com_server_rs485_firmware:1.99:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6ABF4D6-2902-4704-AA2B-E2A914FCE2D6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_com_server_rs485:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE4E1125-7EFF-49D8-AA0C-FC46EE6D614D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:psi-modem\\/eth_firmware:2.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C578559C-D404-4AE5-9CBE-3A21C0C243F0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:psi-modem\\/eth:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "94E2511A-53C9-4EA8-9FAF-E5CC01AB3F46"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_basic_422_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CB3F915-5C96-4A1A-AC9F-78BECE280BA1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_basic_422:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E3EC5C98-27C1-46E9-B121-6C9401F832AB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_basic_485_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2124E060-3182-49A0-A7F7-C0861868C99E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_basic_485:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A24B76B3-709D-44F0-B617-257181D6CDCF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_uni_485-t_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C821C1CE-0A18-41C8-813C-E6763D7DBC01"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_uni_485-t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "08C42753-9D0D-4174-BB62-6F4B590CBC14"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_uni_485_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42B0C8E5-D36C-404A-8355-C49B7FC107CC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_uni_485:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B1870C39-50CD-4206-A6DF-2694651767AA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_uni_232_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DBAC3DD-245E-4092-97CB-F0F5F966382C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_uni_232:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BE602B3C-A730-4DB9-B12B-81540D7E6C66"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_bas_422_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D984EA9-7C6E-424B-B3A7-42E7CA192E23"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_bas_422:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "86C95904-C8C1-4F1D-B844-F36849FA8EA8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixcontact:fl_comserver_bas_232_firmware:2.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11EA5BED-B64E-404A-8614-AFF644B8BB63"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:phoenixcontact:fl_comserver_bas_232:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2EE9C2BC-397C-4A2F-9F66-130A50076781"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}