CVE-2026-22319: CWE-121 Stack-based Buffer Overflow in Phoenix Contact FL SWITCH 2005
A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send oversized POST parameters that overflow a fixed-size stack buffer within an internal process, resulting in a DoS attack.
AI Analysis
Technical Summary
CVE-2026-22319 identifies a stack-based buffer overflow vulnerability classified under CWE-121 in the Phoenix Contact FL SWITCH 2005 industrial network switch. The vulnerability arises during the device's file installation workflow, where the device processes POST requests containing parameters. An attacker with high-level privileges can craft oversized POST parameters that exceed the fixed-size stack buffer allocated within an internal process, causing a buffer overflow. This overflow corrupts the stack memory, leading to a denial-of-service (DoS) condition by crashing or destabilizing the device's internal process. The vulnerability does not allow for code execution or data leakage, as it impacts availability only. Exploitation requires network access and high privileges on the device, but no user interaction is needed. The CVSS v3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) reflects network attack vector, low complexity, high privileges required, no user interaction, unchanged scope, no confidentiality or integrity impact, and high availability impact. No patches or exploits are currently reported, but the vulnerability poses a risk to operational continuity in environments relying on this switch for industrial automation or critical infrastructure networking.
Potential Impact
The primary impact of this vulnerability is denial of service, which can disrupt network operations in industrial or critical infrastructure environments where the FL SWITCH 2005 is deployed. Such disruption can lead to operational downtime, loss of monitoring or control capabilities, and potential cascading effects on dependent systems. Since the vulnerability requires high privileges, it is less likely to be exploited by external attackers without prior access, but insider threats or attackers who have already compromised administrative credentials pose a significant risk. The lack of confidentiality or integrity impact limits data breach concerns, but availability loss in industrial control systems can have serious safety and economic consequences. Organizations relying on these switches for network segmentation or control traffic should consider the risk of service interruption and its operational impact.
Mitigation Recommendations
To mitigate this vulnerability, organizations should first monitor vendor communications for official patches or firmware updates addressing CVE-2026-22319 and apply them promptly once available. In the absence of patches, network segmentation should be enforced to restrict access to the management interfaces of the FL SWITCH 2005 devices to trusted administrators only. Implement strict access controls and multi-factor authentication to reduce the risk of high-privilege credential compromise. Network intrusion detection systems (NIDS) can be configured to detect anomalous oversized POST requests targeting the device's file installation workflow. Additionally, limit the exposure of the device's management interfaces to internal networks and avoid direct internet exposure. Regularly audit device configurations and logs for signs of attempted exploitation. Finally, consider deploying redundant network paths or failover mechanisms to maintain availability if a device becomes unresponsive due to exploitation.
Affected Countries
Germany, United States, China, Japan, South Korea, France, United Kingdom, Italy, Canada, Netherlands
CVE-2026-22319: CWE-121 Stack-based Buffer Overflow in Phoenix Contact FL SWITCH 2005
Description
A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send oversized POST parameters that overflow a fixed-size stack buffer within an internal process, resulting in a DoS attack.
CVSS v3.1
Score 4.9medium
Affected software
Phoenix Contact
FL SWITCH 2005
Phoenix Contact
FL SWITCH 2008
Phoenix Contact
FL SWITCH 2016
Phoenix Contact
FL SWITCH 2105
Phoenix Contact
FL SWITCH 2108
Phoenix Contact
FL SWITCH 2116
Phoenix Contact
FL SWITCH 2204-2TC-2SFX
Phoenix Contact
FL SWITCH 2205
Phoenix Contact
FL SWITCH 2206-2FX
Phoenix Contact
FL SWITCH 2206-2FX SM
Phoenix Contact
FL SWITCH 2206-2FX SM ST
Phoenix Contact
FL SWITCH 2206-2FX ST
Phoenix Contact
FL SWITCH 2206-2SFX
Phoenix Contact
FL SWITCH 2206-2SFX PN
Phoenix Contact
FL SWITCH 2206C-2FX
Phoenix Contact
FL SWITCH 2207-FX
Phoenix Contact
FL SWITCH 2207-FX SM
Phoenix Contact
FL SWITCH 2208
Phoenix Contact
FL SWITCH 2208 PN
Phoenix Contact
FL SWITCH 2208C
Phoenix Contact
FL SWITCH 2212-2TC-2SFX
Phoenix Contact
FL SWITCH 2214-2FX
Phoenix Contact
FL SWITCH 2214-2FX SM
Phoenix Contact
FL SWITCH 2214-2SFX
Phoenix Contact
FL SWITCH 2214-2SFX PN
Phoenix Contact
FL SWITCH 2216
Phoenix Contact
FL SWITCH 2216 PN
Phoenix Contact
FL SWITCH 2304-2GC-2SFP
Phoenix Contact
FL SWITCH 2306-2SFP
Phoenix Contact
FL SWITCH 2306-2SFP PN
Phoenix Contact
FL SWITCH 2308
Phoenix Contact
FL SWITCH 2308 PN
Phoenix Contact
FL SWITCH 2312-2GC-2SFP
Phoenix Contact
FL SWITCH 2314-2SFP
Phoenix Contact
FL SWITCH 2314-2SFP PN
Phoenix Contact
FL SWITCH 2316
Phoenix Contact
FL SWITCH 2316 PN
Phoenix Contact
FL SWITCH 2404-2TC-2SFX
Phoenix Contact
FL SWITCH 2406-2SFX
Phoenix Contact
FL SWITCH 2406-2SFX PN
Phoenix Contact
FL SWITCH 2408
Phoenix Contact
FL SWITCH 2408 PN
Phoenix Contact
FL SWITCH 2412-2TC-2SFX
Phoenix Contact
FL SWITCH 2414-2SFX
Phoenix Contact
FL SWITCH 2414-2SFX PN
Phoenix Contact
FL SWITCH 2416
Phoenix Contact
FL SWITCH 2416 PN
Phoenix Contact
FL SWITCH 2504-2GC-2SFP
Phoenix Contact
FL SWITCH 2506-2SFP
Phoenix Contact
FL SWITCH 2506-2SFP PN
Phoenix Contact
FL SWITCH 2508
Phoenix Contact
FL SWITCH 2508 PN
Phoenix Contact
FL SWITCH 2512-2GC-2SFP
Phoenix Contact
FL SWITCH 2514-2SFP
Phoenix Contact
FL SWITCH 2514-2SFP PN
Phoenix Contact
FL SWITCH 2516
Phoenix Contact
FL SWITCH 2516 PN
Phoenix Contact
FL SWITCH 2608
Phoenix Contact
FL SWITCH 2608 PN
Phoenix Contact
FL SWITCH 2708
Phoenix Contact
FL SWITCH 2708 PN
Phoenix Contact
FL SWITCH 2303-8SP1
Phoenix Contact
FL NAT 2008
Phoenix Contact
FL NAT 2208
Phoenix Contact
FL NAT 2304-2GC-2SFP
Phoenix Contact
FL SWITCH 2008F
Phoenix Contact
FL SWITCH 2316/K1
Phoenix Contact
FL SWITCH 2506-2SFP/K1
Phoenix Contact
FL SWITCH 2508/K1
Phoenix Contact
FL SWITCH TSN 2316
Phoenix Contact
FL SWITCH TSN 2312-2GC-2SFP
Phoenix Contact
FL SWITCH TSN 2314-2SFP
Phoenix Contact
FL SWITCH 5924-4GC
Phoenix Contact
FL SWITCH 5916-8GC-4SFP+
Phoenix Contact
FL SWITCH 5924SFP-4GC
Phoenix Contact
FL SWITCH 5924-4SFP+
Phoenix Contact
FL SWITCH 5916SFP-8GC-4SFP+
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-22319 identifies a stack-based buffer overflow vulnerability classified under CWE-121 in the Phoenix Contact FL SWITCH 2005 industrial network switch. The vulnerability arises during the device's file installation workflow, where the device processes POST requests containing parameters. An attacker with high-level privileges can craft oversized POST parameters that exceed the fixed-size stack buffer allocated within an internal process, causing a buffer overflow. This overflow corrupts the stack memory, leading to a denial-of-service (DoS) condition by crashing or destabilizing the device's internal process. The vulnerability does not allow for code execution or data leakage, as it impacts availability only. Exploitation requires network access and high privileges on the device, but no user interaction is needed. The CVSS v3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) reflects network attack vector, low complexity, high privileges required, no user interaction, unchanged scope, no confidentiality or integrity impact, and high availability impact. No patches or exploits are currently reported, but the vulnerability poses a risk to operational continuity in environments relying on this switch for industrial automation or critical infrastructure networking.
Potential Impact
The primary impact of this vulnerability is denial of service, which can disrupt network operations in industrial or critical infrastructure environments where the FL SWITCH 2005 is deployed. Such disruption can lead to operational downtime, loss of monitoring or control capabilities, and potential cascading effects on dependent systems. Since the vulnerability requires high privileges, it is less likely to be exploited by external attackers without prior access, but insider threats or attackers who have already compromised administrative credentials pose a significant risk. The lack of confidentiality or integrity impact limits data breach concerns, but availability loss in industrial control systems can have serious safety and economic consequences. Organizations relying on these switches for network segmentation or control traffic should consider the risk of service interruption and its operational impact.
Mitigation Recommendations
To mitigate this vulnerability, organizations should first monitor vendor communications for official patches or firmware updates addressing CVE-2026-22319 and apply them promptly once available. In the absence of patches, network segmentation should be enforced to restrict access to the management interfaces of the FL SWITCH 2005 devices to trusted administrators only. Implement strict access controls and multi-factor authentication to reduce the risk of high-privilege credential compromise. Network intrusion detection systems (NIDS) can be configured to detect anomalous oversized POST requests targeting the device's file installation workflow. Additionally, limit the exposure of the device's management interfaces to internal networks and avoid direct internet exposure. Regularly audit device configurations and logs for signs of attempted exploitation. Finally, consider deploying redundant network paths or failover mechanisms to maintain availability if a device becomes unresponsive due to exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2026-01-07T11:49:15.178Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69ba579c771bdb17495548f3
Added to database: 03/18/2026, 07:43:24 UTC
Last enriched: 03/18/2026, 07:58:59 UTC
Last updated: 09/14/2026, 23:02:03 UTC
Views: 189
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.