Back to Database
Status published
High
CVE-2018-13990
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx...
Vulnerability Description
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-13990
Credits & Attribution
No credits recorded in the NVD database.
References
More from phoenixcontact
View All →CVE-2022-22509
PHOENIX CONTACT: FL SWITCH 2xxx series incorrect privilege assignment
High
8.8
CVE-2020-9436
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G...
High
8.8
CVE-2020-9435
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G...
High
7.5
CVE-2020-8768
An issue was discovered on Phoenix Contact Emalytics Controller ILC...
Critical
9.4
CVE-2020-10940
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER...
High
7.8
Affected Vendor
phoenixcontact
View all reports →Affected Software
fl switch 3005 firmware, fl switch 3005t firmware, fl switch 3004t-fx firmware, fl switch 3004t-fx st firmware, fl switch 3008 firmware, fl switch 3008t firmware, fl switch 3006t-2fx firmware, fl switch 3006t-2fx st firmware, fl switch 3012e-2sfx firmware, fl switch 3016e firmware, fl switch 3016 firmware, fl switch 3016t firmware, fl switch 3006t-2fx sm firmware, fl switch 4008t-2sfp firmware, fl switch 4008t-2gt-4fx sm firmware, fl switch 4008t-2gt-3fx sm firmware, fl switch 4808e-16fx lc-4gc firmware, fl switch 4808e-16fx sm-4gc firmware, fl switch 4808e-16fx sm st-4gc firmware, fl switch 4808e-16fx st-4gc firmware, fl switch 4808e-16fx-4gc firmware, fl switch 4808e-16fx sm lc-4gc firmware, fl switch 4012t 2gt 2fx firmware, fl switch 4012t-2gt-2fx st firmware, fl switch 4824e-4gc firmware, fl switch 4800e-24fx-4gc firmware, fl switch 4800e-24fx sm-4gc firmware, fl switch 3012e-2fx sm firmware, fl switch 4000t-8poe-2sfp-r firmware
Vulnerable Versions:
0
Timeline
Official Publish:
May 6th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AC:L/AV:N/A:L/C:H/I:L/PR:N/S:U/UI:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.