ID

VAR-201805-0723


CVE

CVE-2018-10730


TITLE

Phoenix Contact managed FL SWITCH Command injection vulnerability

Trust: 0.8

sources: IVD: e2effbc0-39ab-11e9-986e-000c29342cb1 // CNVD: CNVD-2018-10151

DESCRIPTION

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. PhoenixContact is a German provider of industrial automation, connectivity and interface solutions for critical infrastructure applications such as communications, critical manufacturing and information technology. PhoenixContactmanagedFLSWITCH has a command injection vulnerability. If the configuration file can be transferred to the switch or transferred from the switch, the attacker can upgrade the firmware to execute any OSshell command. An OS command-execution vulnerability 2. An information-disclosure vulnerability 3. Multiple stack-based buffer-overflow vulnerabilities Attackers can exploit these issues to execute arbitrary code, execute arbitrary OS commands, obtain sensitive information, and perform unauthorized actions. Failed exploit attempts will likely cause a denial-of-service condition

Trust: 2.61

sources: NVD: CVE-2018-10730 // JVNDB: JVNDB-2018-005112 // CNVD: CNVD-2018-10151 // BID: 104231 // IVD: e2effbc0-39ab-11e9-986e-000c29342cb1

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: e2effbc0-39ab-11e9-986e-000c29342cb1 // CNVD: CNVD-2018-10151

AFFECTED PRODUCTS

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t-2gt-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx lc-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016escope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4012t 2gt 2fxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-4fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005scope:gtversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2gt-3fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4824e-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4800e-24fx sm-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4000t-8poe-2sfp-rscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3016tscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008tscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4008t-2sfpscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3008scope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm lc-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx smscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3004t-fxscope:lteversion:1.33

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3006t-2fx stscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3012e-2sfxscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 4808e-16fx sm st-4gcscope:gteversion:1.0

Trust: 1.0

vendor:phoenixcontactmodel:fl switch 3005tscope:lteversion:1.33

Trust: 1.0

vendor:phoenix contactmodel:fl switch 3004t-fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3004t-fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3005tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3006t-2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3008tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3012e-2sfxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016scope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016escope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 3016tscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-3fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2gt-4fx smscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4008t-2sfpscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t 2gt 2fxscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4012t-2gt-2fx stscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4800e-24fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx sm-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx st-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4808e-16fx-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenix contactmodel:fl switch 4824e-4gcscope:eqversion:1.0 to 1.33

Trust: 0.8

vendor:phoenixmodel:contact fl switchscope:eqversion:3xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switchscope:eqversion:4xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xxx>=1.0,<=1.32

Trust: 0.6

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:4xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:48xx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx lc-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch seriesscope:eqversion:3xxx1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30161.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30081.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.32

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:eqversion:30051.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.32

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:eqversion:1.0

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4824e-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm st-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4808e-16fx sm lc-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4800e-24fx sm-4gcscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t-2gt-2fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4012t 2gt 2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2sfpscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-4fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4008t-2gt-3fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 4000t-8poe-2sfp-rscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3016escope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30161.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2sfxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3012e-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3008tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30081.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fx smscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3006t-2fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3005tscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switchscope:neversion:30051.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fx stscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch 3004t-fxscope:neversion:1.34

Trust: 0.3

vendor:phoenixmodel:contact fl switch -4804g8ce-16fx lcscope:neversion:1.34

Trust: 0.3

vendor:fl switch 3005model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016emodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3016tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2sfpmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2gt 4fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4008t 2gt 3fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx lc 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm st 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3005tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx st 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4808e 16fx sm lc 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4012t 2gt 2fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4012t 2gt 2fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4824e 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4800e 24fx 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4800e 24fx sm 4gcmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3012e 2fx smmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 4000t 8poe 2sfp rmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3004t fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3004t fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3008model: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3008tmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fxmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3006t 2fx stmodel: - scope:eqversion:*

Trust: 0.2

vendor:fl switch 3012e 2sfxmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: e2effbc0-39ab-11e9-986e-000c29342cb1 // CNVD: CNVD-2018-10151 // BID: 104231 // JVNDB: JVNDB-2018-005112 // NVD: CVE-2018-10730

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-10730
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-10730
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2018-10151
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-518
value: CRITICAL

Trust: 0.6

IVD: e2effbc0-39ab-11e9-986e-000c29342cb1
value: CRITICAL

Trust: 0.2

nvd@nist.gov: CVE-2018-10730
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-10151
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2effbc0-39ab-11e9-986e-000c29342cb1
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2018-10730
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.3
impactScore: 6.0
version: 3.0

Trust: 1.8

sources: IVD: e2effbc0-39ab-11e9-986e-000c29342cb1 // CNVD: CNVD-2018-10151 // JVNDB: JVNDB-2018-005112 // CNNVD: CNNVD-201805-518 // NVD: CVE-2018-10730

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.8

sources: JVNDB: JVNDB-2018-005112 // NVD: CVE-2018-10730

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-518

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201805-518

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005112

PATCH

title:トップページurl:https://www.phoenixcontact.com/online/portal/jp

Trust: 0.8

title:Patch for the PhoenixContactmanagedFLSWITCH command injection vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/130053

Trust: 0.6

title:FL SWITCH 3xxx , 4xxx and 48xxx Series Product Command Injection Vulnerability Fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83450

Trust: 0.6

sources: CNVD: CNVD-2018-10151 // JVNDB: JVNDB-2018-005112 // CNNVD: CNNVD-201805-518

EXTERNAL IDS

db:NVDid:CVE-2018-10730

Trust: 3.5

db:CERT@VDEid:VDE-2018-004

Trust: 3.0

db:ICS CERTid:ICSA-18-137-02

Trust: 2.7

db:BIDid:104231

Trust: 1.3

db:CNVDid:CNVD-2018-10151

Trust: 0.8

db:CNNVDid:CNNVD-201805-518

Trust: 0.8

db:JVNDBid:JVNDB-2018-005112

Trust: 0.8

db:IVDid:E2EFFBC0-39AB-11E9-986E-000C29342CB1

Trust: 0.2

sources: IVD: e2effbc0-39ab-11e9-986e-000c29342cb1 // CNVD: CNVD-2018-10151 // BID: 104231 // JVNDB: JVNDB-2018-005112 // CNNVD: CNNVD-201805-518 // NVD: CVE-2018-10730

REFERENCES

url:https://cert.vde.com/de-de/advisories/vde-2018-004

Trust: 3.0

url:https://ics-cert.us-cert.gov/advisories/icsa-18-137-02

Trust: 2.7

url:http://www.securityfocus.com/bid/104231

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-10730

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-10730

Trust: 0.8

url:https://www.phoenixcontact.com/online/portal/pc

Trust: 0.3

sources: CNVD: CNVD-2018-10151 // BID: 104231 // JVNDB: JVNDB-2018-005112 // CNNVD: CNNVD-201805-518 // NVD: CVE-2018-10730

CREDITS

ERT@VDE working with Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies and PHOENIX CONTACT.

Trust: 0.3

sources: BID: 104231

SOURCES

db:IVDid:e2effbc0-39ab-11e9-986e-000c29342cb1
db:CNVDid:CNVD-2018-10151
db:BIDid:104231
db:JVNDBid:JVNDB-2018-005112
db:CNNVDid:CNNVD-201805-518
db:NVDid:CVE-2018-10730

LAST UPDATE DATE

2024-11-23T22:17:30.174000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-10151date:2018-05-23T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005112date:2018-07-06T00:00:00
db:CNNVDid:CNNVD-201805-518date:2018-05-23T00:00:00
db:NVDid:CVE-2018-10730date:2024-11-21T03:41:56.450

SOURCES RELEASE DATE

db:IVDid:e2effbc0-39ab-11e9-986e-000c29342cb1date:2018-05-23T00:00:00
db:CNVDid:CNVD-2018-10151date:2018-05-23T00:00:00
db:BIDid:104231date:2018-05-17T00:00:00
db:JVNDBid:JVNDB-2018-005112date:2018-07-06T00:00:00
db:CNNVDid:CNNVD-201805-518date:2018-05-17T00:00:00
db:NVDid:CVE-2018-10730date:2018-05-17T19:29:00.400