Phoenixcontact
Phoenixcontact FL Switch 3004t-fx ST Firmware: vulnerabilities and CVEs
Phoenixcontact FL Switch 3004t-fx ST Firmware has 11 published vulnerabilities, 0 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months0
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13994 | High (7.5) | 2.2% | — | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. |
| CVE-2018-13993 | High (8.8) | 0.86% | — | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. |
| CVE-2018-13992 | Critical (9.8) | 1.1% | — | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. |
| CVE-2018-13991 | Medium (5.3) | 1.6% | — | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images. |
| CVE-2018-13990 | Critical (9.8) | 2.3% | — | May 6, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. |
| CVE-2018-10731 | Critical (9) | 2.7% | — | May 17, 2018 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728). |
| CVE-2018-10730 | Critical (9.1) | 4.5% | — | May 17, 2018 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. |
| CVE-2018-10729 | Medium (5.3) | 1.9% | — | May 17, 2018 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user. |
| CVE-2018-10728 | High (8.1) | 2.2% | — | May 17, 2018 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731). |
| CVE-2017-16743 | Critical (9.8) | 3.1% | — | Jan 12, 2018 | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP… |
| CVE-2017-16741 | Medium (5.3) | 1.2% | — | Jan 12, 2018 | An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on… |
Other products by Phoenixcontact
Charx Sec-3100 Firmware · 29Charx Sec-3050 Firmware · 29Charx Sec-3000 Firmware · 29Charx Sec-3150 Firmware · 29FL Mguard Rs4004 Tx/dtx Firmware · 16FL Mguard Rs4004 Tx/dtx VPN Firmware · 16FL Mguard Core TX VPN Firmware · 15FL Mguard Gt/gt VPN Firmware · 15FL Mguard Delta Tx/tx Firmware · 15FL Mguard Delta Tx/tx VPN Firmware · 15FL Mguard Centerport Vpn-1000 Firmware · 15FL Mguard Core TX Firmware · 15