CVE-2018-10731

EUVD-2018-2801
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
phoenixcontactfl_switch_3005_firmware
1.0 <
𝑥
≤ 1.33
phoenixcontactfl_switch_3005t_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3004t-fx_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3004t-fx_st_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3008_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3008t_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3006t-2fx_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3006t-2fx_st_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3012e-2sfx_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3016e_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3016_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3016t_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3006t-2fx_sm_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4008t-2sfp_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4008t-2gt-4fx_sm_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4008t-2gt-3fx_sm_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx_lc-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx_sm-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx_sm_st-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx_st-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4808e-16fx_sm_lc-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4012t_2gt_2fx_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4012t-2gt-2fx_st_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4824e-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4800e-24fx-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4800e-24fx_sm-4gc_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_3012e-2fx_sm_firmware
1.0 ≤
𝑥
≤ 1.33
phoenixcontactfl_switch_4000t-8poe-2sfp-r_firmware
1.0 ≤
𝑥
≤ 1.33
𝑥
= Vulnerable software versions