VYPR

Fl Mguard 4102 Pcie Firmware

by Phoenixcontact

CVEs (14)

  • CVE-2024-7699HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

  • CVE-2024-43388HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

  • CVE-2024-43387HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.

  • CVE-2024-43386HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.

  • CVE-2024-43385HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.

  • CVE-2024-43393HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP…

  • CVE-2024-43392HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable…

  • CVE-2024-43391HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.

  • CVE-2024-43390HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.

  • CVE-2024-43389HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

  • CVE-2024-43384HigMay 7, 2026
    risk 0.52cvss 8.0epss 0.00

    A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

  • CVE-2024-7698MedSep 10, 2024
    risk 0.37cvss 5.7epss 0.00

    A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

  • CVE-2024-7734MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.

  • CVE-2023-2673MedJun 13, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.

VYPR — Vulnerability Intelligence