Vulnerability record · CVE-2022-22509 · published 2 February 2022
CVE-2022-22509: Phoenixcontact fl switch 2005 firmware improper privilege management vulnerability
Phoenixcontact · Fl Switch 2005 Firmware
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
Description
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
65 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-001/ | MitigationThird Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2022-001/ | MitigationThird Party Advisory |
Track CVE-2022-22509 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22509), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.