CVE-2019-9744
—CVSS 3.0
8.8 high
EPSS
2%p75
Published
()
Modified
Description
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.
- Vendors
- phoenixcontact
- Products
- fl nat smn 8tx-m-dmg firmware, fl nat smn 8tx-m firmware, fl nat smn 8tx firmware, fl nat smcs 8tx firmware
- Weakness
- CWE-384
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.