Vulnerability Overview

Phoenix Contact PSIRT and CISA ICS-CERT have released coordinated advisories documenting a critical vulnerability, CVE-2026-65810 (CVSS v3.1 9.8), affecting FL SWITCH 3000 and FL SWITCH 4000 industrial managed Ethernet switches. The vulnerability permits remote, unauthenticated network actors on the control network to execute arbitrary machine instructions on the switch processor or trigger switch reboots, severing real-time PROFINET and EtherNet/IP communications.

Technical Mechanics & Protocol Flow

The FL SWITCH series is a fixture in critical industrial automation, substations, and maritime process plants, providing ring redundancy (MRP/RSTP) and deterministic traffic filtering across Purdue Model Levels 1 and 2. The flaw resides within the embedded SNMP agent handling authenticated and unauthenticated SNMPv1/v2c/v3 request frames on UDP port 161.

When parsing malformed ASN.1 Object Identifiers (OID) within an incoming GetBulk request, the decoding routine miscalculates remaining buffer length during recursive sequence unpacking. An adversary transmitting a crafted UDP packet sequence causes heap buffer corruption, overwriting execution vectors within the real-time embedded kernel.

Purdue Model Impact Flow:
[Control Network Attacker]
       |  (Crafted UDP 161 SNMP ASN.1 Payload)
[Phoenix Contact FL SWITCH 3008T]
       |  (Heap Buffer Overflow in SNMP Daemon)
[Switch Kernel Freeze & Ethernet Port Disconnect]
       |
[MRP Ring Breakage -> SCADA Engineering Workstation Loses PLC Telemetry]

Operational Impact on Critical Infrastructure

When an industrial backbone switch reboots unexpectedly or enters an unrecoverable fault state, the physical consequences can cascade across industrial zones:

  • Ring Redundancy Failure: Rapid port state changes can cause network storms and break Media Redundancy Protocol (MRP) rings, halting automated assembly cells.
  • SCADA Blindness: Human-Machine Interface (HMI) workstations lose communication with safety-critical PLCs and emergency shutdown controllers.
  • Traffic Sniffing: Adversaries achieving persistence on the switch can mirror unencrypted Modbus TCP and CIP industrial traffic for operational intelligence.

Remediation & Hardening Roadmap

Plant automation engineers must execute the following hardening checklist:

  • Flash all Phoenix Contact FL SWITCH 3000 and 4000 hardware to firmware revision V1.60 or higher.
  • Disable SNMP services on any switch interfaces connected to untrusted engineering or enterprise networks.
  • Enforce strict management VLAN isolation ensuring switch configuration consoles are accessible only from dedicated bastion hosts.