ZeroHour

CVE-2018-13992

CVSS 3.0
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

Vendors
phoenixcontact
Products
fl switch 3005 firmware, fl switch 3005t firmware, fl switch 3004t-fx firmware, fl switch 3004t-fx st firmware, fl switch 3008 firmware, fl switch 3008t firmware, fl switch 3006t-2fx firmware, fl switch 3006t-2fx st firmware, fl switch 3012e-2sfx firmware, fl switch 3016e firmware, fl switch 3016 firmware, fl switch 3016t firmware
Weakness
CWE-311
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.