CVE-2018-13992

UnknownEPSS 1.11%

Last modified

CVE-2018-13992 is a vulnerability of currently unknown severity. The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.

Description

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

Metrics

EPSS Probability
1.11%

61.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhoenixcontactFl Switch 3005 Firmware> 1.0, <= 1.34
PhoenixcontactFl Switch 3005t Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3004t-Fx Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3004t-Fx St Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3008 Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3008t Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3006t-2fx Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3006t-2fx St Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3012e-2sfx Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3016e Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3016 Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3016t Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3006t-2fx Sm Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4008t-2sfp Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4008t-2gt-4fx Sm Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4008t-2gt-3fx Sm Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx Lc-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx Sm-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx Sm St-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx St-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4808e-16fx Sm Lc-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4012t 2gt 2fx Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4012t-2gt-2fx St Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4824e-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4800e-24fx-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4800e-24fx Sm-4gc Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 3012e-2fx Sm Firmware>= 1.0, <= 1.34
PhoenixcontactFl Switch 4000t-8poe-2sfp-R Firmware>= 1.0, <= 1.34

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-13992?
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
How severe is CVE-2018-13992?
Severity scoring for CVE-2018-13992 is pending analysis. The EPSS model estimates a 1.11% probability of exploitation in the next 30 days.
How do I fix CVE-2018-13992?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-13992?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST