CVE Database
/

CVE-2020-12523

Back to search

CVE-2020-12523

Published: Dec 17, 2020

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

5.4

MEDIUM

Description

On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource

VendorProductVersions

Phoenix Contact

TC MGUARD RS4000 4G VZW VPN (1010461)

affected
unspecified - < 8.8.3

Phoenix Contact

TC MGUARD RS4000 4G ATT VPN (1010463)

affected
unspecified - < 8.8.3

Phoenix Contact

FL MGUARD RS4004 TX/DTX (2701876)

affected
unspecified - < 8.8.3

Phoenix Contact

FL MGUARD RS4004 TX/DTX VPN (2701877)

affected
unspecified - < 8.8.3

Phoenix Contact

TC MGUARD RS4000 3G VPN (2903440)

affected
unspecified - < 8.8.3

Phoenix Contact

TC MGUARD RS4000 4G VPN (2903586)

affected
unspecified - < 8.8.3

Innominate

Innominate mGuard rs4000 4TX/TX

affected
unspecified - < 8.8.3

Innominate

Innominate mGuard rs4000 4TX/TX VPN

affected
unspecified - < 8.8.3

Innominate

Innominate mGuard rs4000 4TX/3G/TX VPN

affected
unspecified - < 8.8.3

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now