ZeroHour

CVE-2018-13990

CVSS 3.0
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.

Vendors
phoenixcontact
Products
fl switch 3005 firmware, fl switch 3005t firmware, fl switch 3004t-fx firmware, fl switch 3004t-fx st firmware, fl switch 3008 firmware, fl switch 3008t firmware, fl switch 3006t-2fx firmware, fl switch 3006t-2fx st firmware, fl switch 3012e-2sfx firmware, fl switch 3016e firmware, fl switch 3016 firmware, fl switch 3016t firmware
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.