CVE-2024-43385
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
Affected (36)
Products: Phoenixcontact: Tc Mguard Rs4000 4g Vzw Vpn Firmware, Tc Mguard Rs4000 4g Vpn Firmware, Tc Mguard Rs4000 4g Att Vpn Firmware, Tc Mguard Rs4000 3g Vpn Firmware, Tc Mguard Rs2000 4g Vzw Vpn Firmware, Tc Mguard Rs2000 4g Vpn Firmware, Tc Mguard Rs2000 4g Att Vpn Firmware, Tc Mguard Rs2000 3g Vpn Firmware, Fl Mguard Smart2 Vpn Firmware, Fl Mguard Smart2 Firmware, Fl Mguard Rs4004 Tx/dtx Vpn Firmware, Fl Mguard Rs4004 Tx/dtx Firmware, Fl Mguard Rs4000 Tx/tx Vpn Firmware, Fl Mguard Rs4000 Tx/tx P Firmware, Fl Mguard Rs4000 Tx/tx M Firmware, Fl Mguard Rs4000 Tx/tx Firmware, Fl Mguard Rs2005 Tx Vpn Firmware, Fl Mguard Rs2000 Tx/tx Vpn Firmware, Fl Mguard Rs2000 Tx/tx B Firmware, Fl Mguard Pcie4000 Vpn Firmware, Fl Mguard Pcie4000 Firmware, Fl Mguard Pci4000 Vpn Firmware, Fl Mguard Pci4000 Firmware, Fl Mguard Gt/gt Vpn Firmware, Fl Mguard Gt/gt Firmware, Fl Mguard Delta Tx/tx Vpn Firmware, Fl Mguard Delta Tx/tx Firmware, Fl Mguard Core Tx Vpn Firmware, Fl Mguard Core Tx Firmware, Fl Mguard Centerport Vpn 1000 Firmware, Fl Mguard 4305 Firmware, Fl Mguard 4302 Firmware, Fl Mguard 4102 Pcie Firmware, Fl Mguard 4102 Pci Firmware, Fl Mguard 2105 Firmware, Fl Mguard 2102 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs4000 4g Vzw Vpn | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs4000 4g Vpn | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs4000 4g Att Vpn | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs4000 3g Vpn | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs2000 4g Vzw Vpn | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs2000 4g Vpn | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs2000 4g Att Vpn | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Tc Mguard Rs2000 3g Vpn | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Smart2 Vpn | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Smart2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4004 Tx/dtx Vpn | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4004 Tx/dtx | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4000 Tx/tx Vpn | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4000 Tx/tx P | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4000 Tx/tx M | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs4000 Tx/tx | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs2005 Tx Vpn | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs2000 Tx/tx Vpn | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Rs2000 Tx/tx B | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Pcie4000 Vpn | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Pcie4000 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Pci4000 Vpn | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Pci4000 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Gt/gt Vpn | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Gt/gt | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Delta Tx/tx Vpn | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Delta Tx/tx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Core Tx Vpn | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Core Tx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.9.3 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard Centerport Vpn 1000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 4305 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 4302 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 4102 Pcie | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 4102 Pci | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 2105 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.4.1 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fl Mguard 2102 | All versions |
References (1)
Timeline
No history available yet.