Phoenixcontact
Phoenixcontact TC Mguard Rs4000 4G VPN Firmware: vulnerabilidades y CVE
Phoenixcontact TC Mguard Rs4000 4G VPN Firmware tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-43384 | Alta (8) | 0.34% | — | 7 may 2026 | A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. |
| CVE-2024-7699 | Alta (8.8) | 0.76% | — | 10 sept 2024 | An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data. |
| CVE-2024-7698 | Media (5.7) | 0.41% | — | 10 sept 2024 | A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks. |
| CVE-2024-43393 | Alta (8.1) | 0.52% | — | 10 sept 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP… |
| CVE-2024-43392 | Alta (8.1) | 0.52% | — | 10 sept 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP… |
| CVE-2024-43391 | Alta (8.1) | 0.52% | — | 10 sept 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment… |
| CVE-2024-43390 | Alta (8.1) | 0.52% | — | 10 sept 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS. |
| CVE-2024-43389 | Alta (8.1) | 0.52% | — | 10 sept 2024 | A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS. |
| CVE-2024-43388 | Alta (8.8) | 0.56% | — | 10 sept 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. |
| CVE-2024-43387 | Alta (8.8) | 0.56% | — | 10 sept 2024 | A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices. |
| CVE-2024-43386 | Alta (8.8) | 0.74% | — | 10 sept 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices. |
| CVE-2024-43385 | Alta (8.8) | 0.74% | — | 10 sept 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices. |
| CVE-2024-7734 | Media (5.3) | 0.48% | — | 10 sept 2024 | An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited… |
| CVE-2022-3480 | Alta (7.5) | 0.91% | — | 15 nov 2022 | A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from… |
| CVE-2020-12523 | Crítica (9.1) | 0.90% | — | 17 dic 2020 | On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phoenixcontact
Charx Sec-3150 Firmware · 29Charx Sec-3050 Firmware · 29Charx Sec-3000 Firmware · 29Charx Sec-3100 Firmware · 29FL Mguard Rs4004 Tx/dtx VPN Firmware · 16FL Mguard Rs4004 Tx/dtx Firmware · 16FL Switch 2416 PN Firmware · 15FL Switch 2316 Firmware · 15FL Mguard Gt/gt Firmware · 15FL NAT 2208 Firmware · 15FL Switch 2214-2fx SM Firmware · 15FL Switch 2314-2sfp Firmware · 15