CVE-2018-13992
published 2019-05-07CVE-2018-13992: The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.5th percentile
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | fl_switch_3004t-fx_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3004t-fx_st_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3005_firmware | <= 1.34 | — |
| phoenixcontact | fl_switch_3005t_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3006t-2fx_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3006t-2fx_sm_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3006t-2fx_st_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3008_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3008t_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3012e-2fx_sm_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3012e-2sfx_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3016_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3016e_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_3016t_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4000t-8poe-2sfp-r_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4008t-2gt-3fx_sm_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4008t-2gt-4fx_sm_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4008t-2sfp_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4012t-2gt-2fx_st_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4012t_2gt_2fx_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4800e-24fx-4gc_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4800e-24fx_sm-4gc_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4808e-16fx-4gc_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4808e-16fx_lc-4gc_firmware | 1.0 – 1.34 | — |
| phoenixcontact | fl_switch_4808e-16fx_sm-4gc_firmware | 1.0 – 1.34 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9g7-24wc-gw4q: The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1
ghsa_unreviewed·2022-05-24
CVE-2018-13992 [CRITICAL] CWE-311 GHSA-m9g7-24wc-gw4q: The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
CISA ICS
PHOENIX CONTACT FL SWITCH
cisa_ics·2019-01-24·CVSS 8.6
[HIGH] PHOENIX CONTACT FL SWITCH
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PHOENIX CONTACT FL SWITCH
Last RevisedJanuary 24, 2019
Alert CodeICSA-19-024-02
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: PHOENIX CONTACT
- Equipment: FL SWITCH
- Vulnerabilities: Cross-site Request Forgery, Improper Restriction of Excessive Authentication Attempts, Cleartext Transmission of Sensitive Information, Resource Exhaustion, Incorrectly Specified Destination in a Communication Channel, Insecure Storage of Sensitive Information, and Memory Corruption
## 2. RISK EVALUATION
Successful exploitation of
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-07
Published