445
VMScore

CVE-2018-13991

Published: 07/05/2019 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact fl_switch_3005_firmware

phoenixcontact fl_switch_3005t_firmware

phoenixcontact fl_switch_3004t-fx_firmware

phoenixcontact fl_switch_3004t-fx_st_firmware

phoenixcontact fl_switch_3008_firmware

phoenixcontact fl_switch_3008t_firmware

phoenixcontact fl_switch_3006t-2fx_firmware

phoenixcontact fl_switch_3006t-2fx_st_firmware

phoenixcontact fl_switch_3012e-2sfx_firmware

phoenixcontact fl_switch_3016e_firmware

phoenixcontact fl_switch_3016_firmware

phoenixcontact fl_switch_3016t_firmware

phoenixcontact fl_switch_3006t-2fx_sm_firmware

phoenixcontact fl_switch_4008t-2sfp_firmware

phoenixcontact fl_switch_4008t-2gt-4fx_sm_firmware

phoenixcontact fl_switch_4008t-2gt-3fx_sm_firmware

phoenixcontact fl_switch_4808e-16fx_lc-4gc_firmware

phoenixcontact fl_switch_4808e-16fx_sm-4gc_firmware

phoenixcontact fl_switch_4808e-16fx_sm_st-4gc_firmware

phoenixcontact fl_switch_4808e-16fx_st-4gc_firmware

phoenixcontact fl_switch_4808e-16fx-4gc_firmware

phoenixcontact fl_switch_4808e-16fx_sm_lc-4gc_firmware

phoenixcontact fl_switch_4012t_2gt_2fx_firmware

phoenixcontact fl_switch_4012t-2gt-2fx_st_firmware

phoenixcontact fl_switch_4824e-4gc_firmware

phoenixcontact fl_switch_4800e-24fx-4gc_firmware

phoenixcontact fl_switch_4800e-24fx_sm-4gc_firmware

phoenixcontact fl_switch_3012e-2fx_sm_firmware

phoenixcontact fl_switch_4000t-8poe-2sfp-r_firmware

Recent Articles

Network kit biz Phoenix takes heat as flaws may leave industrial control system security in ashes
The Register • Shaun Nichols in San Francisco • 11 Feb 2019

Oil, gas, maritime systems affected by latest bug findings Yes, you can remotely hack factory, building site cranes. Wait, what?

Companies running a popular brand of industrial Ethernet switch are being advised to update their firmware ASAP following a series of bug disclosures. Security house Positive Technologies took credit today for the discovery of six CVE-listed security vulnerabilities in the Phoenix Contact FL Switch 3xxx, 4xxx, and 48xx industrial control switches. The flaws are addressed in firmware versions 1.35 or newer. Among the now-patched flaws were several Positive described as "critical" security risks t...