ID

VAR-201805-0693


CVE

CVE-2018-10731


TITLE

plural Phoenix Contact FL SWITCH Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-005167

DESCRIPTION

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728). plural Phoenix Contact FL SWITCH The product contains a buffer error vulnerability. This vulnerability CVE-2018-10728 Is a different vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. PHOENIXCONTACTFLSWITCH3xxx, 4xxx and 48xxxSeries are all different series of switch devices from the Phoenix Contact group in Germany. A stack buffer overflow vulnerability exists in PHOENIXCONTACTFLSWITCH3xxx, 4xxx, and 48xxxSeries products using firmware versions 1.0 through 1.32. A remote attacker could exploit the vulnerability to gain unauthorized access to the switch operating system files and to inject executable code into the operating system. An OS command-execution vulnerability 2. An information-disclosure vulnerability 3. Multiple stack-based buffer-overflow vulnerabilities Attackers can exploit these issues to execute arbitrary code, execute arbitrary OS commands, obtain sensitive information, and perform unauthorized actions. Failed exploit attempts will likely cause a denial-of-service condition

Trust: 2.43

sources: NVD: CVE-2018-10731 // JVNDB: JVNDB-2018-005167 // CNVD: CNVD-2018-14414 // BID: 104231

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-14414

AFFECTED PRODUCTS

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:gtversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:lteversion:1.33

Trust: 1.0

vendor:phoenix contactmodel:fl switch 3004t-fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3004t-fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2sfxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016escope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-3fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-4fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2sfpscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t 2gt 2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t-2gt-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4824e-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30161.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30081.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30051.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch -4804g8ce-16fx lcscope:neversion:1.34

Trust: 0.3

sources: CNVD: CNVD-2018-14414 // BID: 104231 // JVNDB: JVNDB-2018-005167 // NVD: CVE-2018-10731

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-10731
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-10731
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2018-14414
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-517
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2018-10731
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-14414
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-10731
baseSeverity: CRITICAL
baseScore: 9.0
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 6.0
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-14414 // JVNDB: JVNDB-2018-005167 // CNNVD: CNNVD-201805-517 // NVD: CVE-2018-10731

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2018-005167 // NVD: CVE-2018-10731

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-517

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201805-517

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005167

PATCH

title:Top Pageurl:https://www.phoenixcontact.com/online/portal/pc

Trust: 0.8

title:PHOENIX CONTACT FL SWITCH 3xxx , 4xxx and 48xxx Series Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83449

Trust: 0.6

sources: JVNDB: JVNDB-2018-005167 // CNNVD: CNNVD-201805-517

EXTERNAL IDS

db:NVDid:CVE-2018-10731

Trust: 3.3

db:CERT@VDEid:VDE-2018-007

Trust: 2.4

db:ICS CERTid:ICSA-18-137-02

Trust: 2.1

db:BIDid:104231

Trust: 1.9

db:JVNDBid:JVNDB-2018-005167

Trust: 0.8

db:CNVDid:CNVD-2018-14414

Trust: 0.6

db:CNNVDid:CNNVD-201805-517

Trust: 0.6

sources: CNVD: CNVD-2018-14414 // BID: 104231 // JVNDB: JVNDB-2018-005167 // CNNVD: CNNVD-201805-517 // NVD: CVE-2018-10731

REFERENCES

url:https://cert.vde.com/de-de/advisories/vde-2018-007

Trust: 2.4

url:https://ics-cert.us-cert.gov/advisories/icsa-18-137-02

Trust: 2.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-10731

Trust: 1.4

url:http://www.securityfocus.com/bid/104231

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-10731

Trust: 0.8

url:https://www.phoenixcontact.com/online/portal/pc

Trust: 0.3

sources: CNVD: CNVD-2018-14414 // BID: 104231 // JVNDB: JVNDB-2018-005167 // CNNVD: CNNVD-201805-517 // NVD: CVE-2018-10731

CREDITS

ERT@VDE working with Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies and PHOENIX CONTACT.

Trust: 0.3

sources: BID: 104231

SOURCES

db:CNVDid:CNVD-2018-14414
db:BIDid:104231
db:JVNDBid:JVNDB-2018-005167
db:CNNVDid:CNNVD-201805-517
db:NVDid:CVE-2018-10731

LAST UPDATE DATE

2024-11-23T22:17:30.214000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-14414date:2018-08-01T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005167date:2018-07-09T00:00:00
db:CNNVDid:CNNVD-201805-517date:2018-05-23T00:00:00
db:NVDid:CVE-2018-10731date:2024-11-21T03:41:56.613

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-14414date:2018-08-01T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005167date:2018-07-09T00:00:00
db:CNNVDid:CNNVD-201805-517date:2018-05-17T00:00:00
db:NVDid:CVE-2018-10731date:2018-05-17T19:29:00.447