// For flags

CVE-2019-9744

 

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.

Se ha descubierto un problema en dispositivos PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M y FL NAT SMN 8TX-M-DMG. Hay un acceso no autorizado al WEB-UI por parte de los atacantes que llegan desde la misma dirección IP de origen que un usuario autenticado, ya que esta dirección se emplea como identificador de sesión.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-03-13 CVE Reserved
  • 2019-03-26 CVE Published
  • 2024-03-19 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-384: Session Fixation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx-m-dmg Firmware
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx-m-dmg Firmware"
--
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx-m-dmg
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx-m-dmg"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx-m Firmware
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx-m Firmware"
--
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx-m
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx-m"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx Firmware
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx Firmware"
--
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smn 8tx
Search vendor "Phoenixcontact" for product "Fl Nat Smn 8tx"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smcs 8tx Firmware
Search vendor "Phoenixcontact" for product "Fl Nat Smcs 8tx Firmware"
--
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Fl Nat Smcs 8tx
Search vendor "Phoenixcontact" for product "Fl Nat Smcs 8tx"
--
Safe