5.3
CVSSv3

CVE-2018-13991

Published: 07/05/2019 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact fl switch 3005 firmware

phoenixcontact fl switch 3005t firmware

phoenixcontact fl switch 3004t-fx firmware

phoenixcontact fl switch 3004t-fx st firmware

phoenixcontact fl switch 3008 firmware

phoenixcontact fl switch 3008t firmware

phoenixcontact fl switch 3006t-2fx firmware

phoenixcontact fl switch 3006t-2fx st firmware

phoenixcontact fl switch 3012e-2sfx firmware

phoenixcontact fl switch 3016e firmware

phoenixcontact fl switch 3016 firmware

phoenixcontact fl switch 3016t firmware

phoenixcontact fl switch 3006t-2fx sm firmware

phoenixcontact fl switch 4008t-2sfp firmware

phoenixcontact fl switch 4008t-2gt-4fx sm firmware

phoenixcontact fl switch 4008t-2gt-3fx sm firmware

phoenixcontact fl switch 4808e-16fx lc-4gc firmware

phoenixcontact fl switch 4808e-16fx sm-4gc firmware

phoenixcontact fl switch 4808e-16fx sm st-4gc firmware

phoenixcontact fl switch 4808e-16fx st-4gc firmware

phoenixcontact fl switch 4808e-16fx-4gc firmware

phoenixcontact fl switch 4808e-16fx sm lc-4gc firmware

phoenixcontact fl switch 4012t 2gt 2fx firmware

phoenixcontact fl switch 4012t-2gt-2fx st firmware

phoenixcontact fl switch 4824e-4gc firmware

phoenixcontact fl switch 4800e-24fx-4gc firmware

phoenixcontact fl switch 4800e-24fx sm-4gc firmware

phoenixcontact fl switch 3012e-2fx sm firmware

phoenixcontact fl switch 4000t-8poe-2sfp-r firmware

Recent Articles

Network kit biz Phoenix takes heat as flaws may leave industrial control system security in ashes
The Register • Shaun Nichols in San Francisco • 11 Feb 2019

Oil, gas, maritime systems affected by latest bug findings Yes, you can remotely hack factory, building site cranes. Wait, what?

Companies running a popular brand of industrial Ethernet switch are being advised to update their firmware ASAP following a series of bug disclosures. Security house Positive Technologies took credit today for the discovery of six CVE-listed security vulnerabilities in the Phoenix Contact FL Switch 3xxx, 4xxx, and 48xx industrial control switches. The flaws are addressed in firmware versions 1.35 or newer. Among the now-patched flaws were several Positive described as "critical" security risks t...