CVE-2018-5441
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.
Affected (23)
Products: Phoenixcontact: Mguard Centerport Firmware, Mguard Delta Tx/tx Firmware, Mguard Delta Tx/tx Vpn Firmware, Mguard Gt/gt Firmware, Mguard Gt/gt Vpn Firmware, Mguard Pci4000 Vpn Firmware, Mguard Pcie4000 Vpn Firmware, Mguard Rs2000 Tx/tx Vpn Firmware, Mguard Rs2000 Tx/tx B Firmware, Mguard Rs2005 Tx Vpn Firmware, Mguard Rs4000 Tx/tx Firmware, Mguard Rs4000 Tx/tx Vpn Firmware, Mguard Rs4000 Tx/tx Vpn M Firmware, Mguard Rs4000 Tx/tx P Firmware, Mguard Rs4004 Tx/dtx Firmware, Mguard Rs4004 Tx/dtx Vpn Firmware, Mguard Smart2 Firmware, Mguard Smart2 Vpn Firmware, Mguard Rs2000 3g Vpn Firmware, Mguard Rs4000 3g Vpn Firmware, Mguard Core Tx Vpn Firmware, Mguard Rs2000 4g Vpn Firmware, Mguard Rs4000 4g Vpn Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Centerport | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Delta Tx/tx | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Delta Tx/tx Vpn | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Gt/gt | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Gt/gt Vpn | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Pci4000 Vpn | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Pcie4000 Vpn | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs2000 Tx/tx Vpn | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs2000 Tx/tx B | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs2005 Tx Vpn | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 Tx/tx | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 Tx/tx Vpn | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 Tx/tx Vpn M | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 Tx/tx P | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4004 Tx/dtx | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4004 Tx/dtx Vpn | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Smart2 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Smart2 Vpn | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs2000 3g Vpn | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 3g Vpn | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Core Tx Vpn | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs2000 4g Vpn | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.0 to 8.6.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Mguard Rs4000 4g Vpn | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-354
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
References (6)
Source: ics-cert@hq.dhs.gov
PatchThird Party Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.