Product:

Fl_mguard_centerport_vpn\-1000_firmware

(Phoenixcontact)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 14
Date Id Summary Products Score Patch Annotated
2022-11-15 CVE-2022-3480 A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue. Fl_mguard_centerport_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware N/A
2023-06-13 CVE-2023-2673 Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks. Fl_mguard_2102_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_centerport_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware N/A
2024-09-10 CVE-2024-43389 A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.1
2024-09-10 CVE-2024-43391 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.1
2024-09-10 CVE-2024-43390 A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.1
2024-09-10 CVE-2024-43392 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS. Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.1
2024-09-10 CVE-2024-43393 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.1
2024-09-10 CVE-2024-7734 An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 5.3
2024-09-10 CVE-2024-43385 A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.8
2024-09-10 CVE-2024-43386 A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices. Fl_mguard_2102_firmware, Fl_mguard_2105_firmware, Fl_mguard_4102_pci_firmware, Fl_mguard_4102_pcie_firmware, Fl_mguard_4302_firmware, Fl_mguard_4305_firmware, Fl_mguard_centerport_vpn\-1000_firmware, Fl_mguard_core_tx_firmware, Fl_mguard_core_tx_vpn_firmware, Fl_mguard_delta_tx\/tx_firmware, Fl_mguard_delta_tx\/tx_vpn_firmware, Fl_mguard_gt\/gt_firmware, Fl_mguard_gt\/gt_vpn_firmware, Fl_mguard_pci4000_firmware, Fl_mguard_pci4000_vpn_firmware, Fl_mguard_pcie4000_firmware, Fl_mguard_pcie4000_vpn_firmware, Fl_mguard_rs2000_tx\/tx\-B_firmware, Fl_mguard_rs2000_tx\/tx_vpn_firmware, Fl_mguard_rs2005_tx_vpn_firmware, Fl_mguard_rs4000_tx\/tx\-M_firmware, Fl_mguard_rs4000_tx\/tx\-P_firmware, Fl_mguard_rs4000_tx\/tx_firmware, Fl_mguard_rs4000_tx\/tx_vpn_firmware, Fl_mguard_rs4004_tx\/dtx_firmware, Fl_mguard_rs4004_tx\/dtx_vpn_firmware, Fl_mguard_smart2_firmware, Fl_mguard_smart2_vpn_firmware, Tc_mguard_rs2000_3g_vpn_firmware, Tc_mguard_rs2000_4g_att_vpn_firmware, Tc_mguard_rs2000_4g_vpn_firmware, Tc_mguard_rs2000_4g_vzw_vpn_firmware, Tc_mguard_rs4000_3g_vpn_firmware, Tc_mguard_rs4000_4g_att_vpn_firmware, Tc_mguard_rs4000_4g_vpn_firmware, Tc_mguard_rs4000_4g_vzw_vpn_firmware 8.8