← Volver a CVEs
CVE-2018-13990
N/ADescripcion
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado5/6/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
phoenixcontact:fl_switch_3004t-fxphoenixcontact:fl_switch_3004t-fx_firmwarephoenixcontact:fl_switch_3004t-fx_stphoenixcontact:fl_switch_3004t-fx_st_firmwarephoenixcontact:fl_switch_3005phoenixcontact:fl_switch_3005_firmwarephoenixcontact:fl_switch_3005tphoenixcontact:fl_switch_3005t_firmwarephoenixcontact:fl_switch_3006t-2fxphoenixcontact:fl_switch_3006t-2fx_firmwarephoenixcontact:fl_switch_3006t-2fx_smphoenixcontact:fl_switch_3006t-2fx_sm_firmwarephoenixcontact:fl_switch_3006t-2fx_stphoenixcontact:fl_switch_3006t-2fx_st_firmwarephoenixcontact:fl_switch_3008phoenixcontact:fl_switch_3008_firmwarephoenixcontact:fl_switch_3008tphoenixcontact:fl_switch_3008t_firmwarephoenixcontact:fl_switch_3012e-2fx_smphoenixcontact:fl_switch_3012e-2fx_sm_firmwarephoenixcontact:fl_switch_3012e-2sfxphoenixcontact:fl_switch_3012e-2sfx_firmwarephoenixcontact:fl_switch_3016phoenixcontact:fl_switch_3016_firmwarephoenixcontact:fl_switch_3016ephoenixcontact:fl_switch_3016e_firmwarephoenixcontact:fl_switch_3016tphoenixcontact:fl_switch_3016t_firmwarephoenixcontact:fl_switch_4000t-8poe-2sfp-rphoenixcontact:fl_switch_4000t-8poe-2sfp-r_firmwarephoenixcontact:fl_switch_4008t-2gt-3fx_smphoenixcontact:fl_switch_4008t-2gt-3fx_sm_firmwarephoenixcontact:fl_switch_4008t-2gt-4fx_smphoenixcontact:fl_switch_4008t-2gt-4fx_sm_firmwarephoenixcontact:fl_switch_4008t-2sfpphoenixcontact:fl_switch_4008t-2sfp_firmwarephoenixcontact:fl_switch_4012t-2gt-2fx_stphoenixcontact:fl_switch_4012t-2gt-2fx_st_firmwarephoenixcontact:fl_switch_4012t_2gt_2fxphoenixcontact:fl_switch_4012t_2gt_2fx_firmwarephoenixcontact:fl_switch_4800e-24fx-4gcphoenixcontact:fl_switch_4800e-24fx-4gc_firmwarephoenixcontact:fl_switch_4800e-24fx_sm-4gcphoenixcontact:fl_switch_4800e-24fx_sm-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx-4gcphoenixcontact:fl_switch_4808e-16fx-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx_lc-4gcphoenixcontact:fl_switch_4808e-16fx_lc-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx_sm-4gcphoenixcontact:fl_switch_4808e-16fx_sm-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx_sm_lc-4gcphoenixcontact:fl_switch_4808e-16fx_sm_lc-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx_sm_st-4gcphoenixcontact:fl_switch_4808e-16fx_sm_st-4gc_firmwarephoenixcontact:fl_switch_4808e-16fx_st-4gcphoenixcontact:fl_switch_4808e-16fx_st-4gc_firmwarephoenixcontact:fl_switch_4824e-4gcphoenixcontact:fl_switch_4824e-4gc_firmware
Debilidades (CWE)
CWE-287
Referencias
http://www.securityfocus.com/bid/106737(cve@mitre.org)
https://ics-cert.us-cert.gov/advisories/ICSA-19-024-02(cve@mitre.org)
http://www.securityfocus.com/bid/106737(af854a3a-2127-422b-91ae-364da2661108)
https://ics-cert.us-cert.gov/advisories/ICSA-19-024-02(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.