CVE-2018-13992 PUBLISHED CVSS 8.199999809265137 HIGH

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

EPSS 0.17% · 37.8th percentile

Risk Scores

CVSS v3.0
8.199999809265137
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:L/PR:N/S:U/UI:N
EPSS Score
0.17%
37.8th percentile

Affected Products

VendorProductVersions
phoenixcontactfl_switch_3016t_firmware1.0
phoenixcontactfl_switch_3016_firmware1.0
phoenixcontactfl_switch_4808e-16fx_st-4gc_firmware1.0
phoenixcontactfl_switch_4808e-16fx_lc-4gc_firmware1.0
phoenixcontactfl_switch_3006t-2fx_firmware1.0
phoenixcontactfl_switch_4800e-24fx-4gc_firmware1.0
phoenixcontactfl_switch_4000t-8poe-2sfp-r_firmware1.0
phoenixcontactfl_switch_4012t_2gt_2fx_firmware1.0
phoenixcontactfl_switch_4800e-24fx_sm-4gc_firmware1.0
n/an/an/a
phoenixcontactfl_switch_3012e-2sfx_firmware1.0
phoenixcontactfl_switch_3005_firmware1.0
phoenixcontactfl_switch_4008t-2gt-3fx_sm_firmware1.0
phoenixcontactfl_switch_3012e-2fx_sm_firmware1.0
phoenixcontactfl_switch_3004t-fx_st_firmware1.0
phoenixcontactfl_switch_4008t-2gt-4fx_sm_firmware1.0
phoenixcontactfl_switch_4824e-4gc_firmware1.0
phoenixcontactfl_switch_3016e_firmware1.0
phoenixcontactfl_switch_4012t-2gt-2fx_st_firmware1.0
phoenixcontactfl_switch_3004t-fx_firmware1.0

…and 10 more

Timeline

References

Open in Interactive Console →