ID

VAR-201805-0721


CVE

CVE-2018-10728


TITLE

Phoenix Contact managed FL SWITCH Buffer Overflow Vulnerability

Trust: 0.8

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNVD: CNVD-2018-10149

DESCRIPTION

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731). plural Phoenix Contact FL SWITCH The product contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. PhoenixContact is a German provider of industrial automation, connectivity and interface solutions for critical infrastructure applications such as communications, critical manufacturing and information technology. PhoenixContactmanagedFLSWITCH has a buffer overflow vulnerability that allows an attacker to insert a specially crafted cookie into a GET request to cause a buffer overflow, thereby triggering a denial of service attack and executing arbitrary code. An OS command-execution vulnerability 2. An information-disclosure vulnerability 3. Multiple stack-based buffer-overflow vulnerabilities Attackers can exploit these issues to execute arbitrary code, execute arbitrary OS commands, obtain sensitive information, and perform unauthorized actions. Failed exploit attempts will likely cause a denial-of-service condition

Trust: 2.61

sources: NVD: CVE-2018-10728 // JVNDB: JVNDB-2018-005165 // CNVD: CNVD-2018-10149 // BID: 104231 // IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNVD: CNVD-2018-10149

AFFECTED PRODUCTS

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:gtversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:lteversion:1.33

Trust: 1.0

vendor:phoenix contactmodel:fl switch 3004t-fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3004t-fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2sfxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016escope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-3fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-4fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2sfpscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t 2gt 2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t-2gt-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4824e-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenixmodel:contact fl switchscope:eqversion:3xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switchscope:eqversion:4xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30161.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30081.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30051.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch -4804g8ce-16fx lcscope:neversion:1.34

Trust: 0.3

vendor:fl switch 3005model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016emodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2sfpmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2gt 4fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2gt 3fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx lc 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm st 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3005tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx st 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm lc 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4012t 2gt 2fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4012t 2gt 2fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4824e 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4800e 24fx 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4800e 24fx sm 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3012e 2fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4000t 8poe 2sfp rmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3004t fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3004t fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3008model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3008tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3012e 2sfxmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNVD: CNVD-2018-10149 // BID: 104231 // JVNDB: JVNDB-2018-005165 // NVD: CVE-2018-10728

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-10728
value: HIGH

Trust: 1.0

NVD: CVE-2018-10728
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-10149
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-520
value: MEDIUM

Trust: 0.6

IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2018-10728
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-10149
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2018-10728
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNVD: CNVD-2018-10149 // JVNDB: JVNDB-2018-005165 // CNNVD: CNNVD-201805-520 // NVD: CVE-2018-10728

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2018-005165 // NVD: CVE-2018-10728

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-520

TYPE

Buffer overflow

Trust: 0.8

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNNVD: CNNVD-201805-520

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005165

PATCH

title:Top Pageurl:https://www.phoenixcontact.com/online/portal/pc

Trust: 0.8

title:Patch for PhoenixContactmanagedFLSWITCH Buffer Overflow Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/130067

Trust: 0.6

title:PHOENIX CONTACT FL SWITCH 3xxx , 4xxx and 48xxx Series Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83452

Trust: 0.6

sources: CNVD: CNVD-2018-10149 // JVNDB: JVNDB-2018-005165 // CNNVD: CNNVD-201805-520

EXTERNAL IDS

db:NVDid:CVE-2018-10728

Trust: 3.5

db:CERT@VDEid:VDE-2018-006

Trust: 3.0

db:ICS CERTid:ICSA-18-137-02

Trust: 2.7

db:BIDid:104231

Trust: 1.3

db:CNVDid:CNVD-2018-10149

Trust: 0.8

db:CNNVDid:CNNVD-201805-520

Trust: 0.8

db:JVNDBid:JVNDB-2018-005165

Trust: 0.8

db:IVDid:E2EFD4B0-39AB-11E9-8585-000C29342CB1

Trust: 0.2

sources: IVD: e2efd4b0-39ab-11e9-8585-000c29342cb1 // CNVD: CNVD-2018-10149 // BID: 104231 // JVNDB: JVNDB-2018-005165 // CNNVD: CNNVD-201805-520 // NVD: CVE-2018-10728

REFERENCES

url:https://cert.vde.com/de-de/advisories/vde-2018-006

Trust: 3.0

url:https://ics-cert.us-cert.gov/advisories/icsa-18-137-02

Trust: 2.7

url:http://www.securityfocus.com/bid/104231

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-10728

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-10728

Trust: 0.8

url:https://www.phoenixcontact.com/online/portal/pc

Trust: 0.3

sources: CNVD: CNVD-2018-10149 // BID: 104231 // JVNDB: JVNDB-2018-005165 // CNNVD: CNNVD-201805-520 // NVD: CVE-2018-10728

CREDITS

ERT@VDE working with Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies and PHOENIX CONTACT.

Trust: 0.3

sources: BID: 104231

SOURCES

db:IVDid:e2efd4b0-39ab-11e9-8585-000c29342cb1
db:CNVDid:CNVD-2018-10149
db:BIDid:104231
db:JVNDBid:JVNDB-2018-005165
db:CNNVDid:CNNVD-201805-520
db:NVDid:CVE-2018-10728

LAST UPDATE DATE

2024-11-23T22:17:30.095000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-10149date:2018-05-23T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005165date:2018-07-09T00:00:00
db:CNNVDid:CNNVD-201805-520date:2018-05-23T00:00:00
db:NVDid:CVE-2018-10728date:2024-11-21T03:41:56.097

SOURCES RELEASE DATE

db:IVDid:e2efd4b0-39ab-11e9-8585-000c29342cb1date:2018-05-23T00:00:00
db:CNVDid:CNVD-2018-10149date:2018-05-23T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005165date:2018-07-09T00:00:00
db:CNNVDid:CNNVD-201805-520date:2018-05-17T00:00:00
db:NVDid:CVE-2018-10728date:2018-05-17T19:29:00.307