Lucene search

K
cve[email protected]CVE-2022-3480
HistoryNov 15, 2022 - 11:15 a.m.

CVE-2022-3480

2022-11-1511:15:12
CWE-770
web.nvd.nist.gov
37
2
cve-2022-3480
phoenix contact
fl mguard
tc mguard
denial-of-service
unauthenticated
https
firewall limits
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.4%

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.

Affected configurations

NVD
Node
phoenixcontactfl_mguard_centerport_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_centerportMatch-
Node
phoenixcontactfl_mguard_centerport_vpn-1000_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_centerport_vpn-1000Match-
Node
phoenixcontactfl_mguard_core_tx_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_core_txMatch-
Node
phoenixcontactfl_mguard_core_tx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_core_tx_vpnMatch-
Node
phoenixcontactfl_mguard_delta_tx\/tx_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_delta_tx\/txMatch-
Node
phoenixcontactfl_mguard_delta_tx\/tx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_delta_tx\/tx_vpnMatch-
Node
phoenixcontactfl_mguard_gt\/gt_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_gt\/gtMatch-
Node
phoenixcontactfl_mguard_gt\/gt_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_gt\/gt_vpnMatch-
Node
phoenixcontactfl_mguard_pci4000_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_pci4000Match-
Node
phoenixcontactfl_mguard_pci4000_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_pci4000_vpnMatch-
Node
phoenixcontactfl_mguard_pcie4000_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_pcie4000Match-
Node
phoenixcontactfl_mguard_pcie4000_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_pcie4000_vpnMatch-
Node
phoenixcontactfl_mguard_rs2000_tx\/tx-b_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs2000_tx\/tx-bMatch-
Node
phoenixcontactfl_mguard_rs2000_tx\/tx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs2000_tx\/tx_vpnMatch-
Node
phoenixcontactfl_mguard_rs2005_tx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs2005_tx_vpnMatch-
Node
phoenixcontactfl_mguard_rs4000_tx\/tx_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4000_tx\/txMatch-
Node
phoenixcontactfl_mguard_rs4000_tx\/tx-m_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4000_tx\/tx-mMatch-
Node
phoenixcontactfl_mguard_rs4000_tx\/tx-p_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4000_tx\/tx-pMatch-
Node
phoenixcontactfl_mguard_rs4000_tx\/tx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4000_tx\/tx_vpnMatch-
Node
phoenixcontactfl_mguard_rs4004_tx\/dtx_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4004_tx\/dtxMatch-
Node
phoenixcontactfl_mguard_rs4004_tx\/dtx_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_rs4004_tx\/dtx_vpnMatch-
Node
phoenixcontactfl_mguard_smart2_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_smart2Match-
Node
phoenixcontactfl_mguard_smart2_vpn_firmwareRange<8.9.0
AND
phoenixcontactfl_mguard_smart2_vpnMatch-
Node
phoenixcontacttc_mguard_rs2000_3g_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs2000_3g_vpnMatch-
Node
phoenixcontacttc_mguard_rs2000_4g_att_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs2000_4g_att_vpnMatch-
Node
phoenixcontacttc_mguard_rs2000_4g_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs2000_4g_vpnMatch-
Node
phoenixcontacttc_mguard_rs2000_4g_vzw_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs2000_4g_vzw_vpnMatch-
Node
phoenixcontacttc_mguard_rs4000_3g_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs4000_3g_vpnMatch-
Node
phoenixcontacttc_mguard_rs4000_4g_att_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs4000_4g_att_vpnMatch-
Node
phoenixcontacttc_mguard_rs4000_4g_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs4000_4g_vpnMatch-
Node
phoenixcontacttc_mguard_rs4000_4g_vzw_vpn_firmwareRange<8.9.0
AND
phoenixcontacttc_mguard_rs4000_4g_vzw_vpnMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CENTERPORT",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CENTERPORT VPN-1000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CORE TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CORE TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD DELTA TX/TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD DELTA TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD GT/GT",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD GT/GT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCI4000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCI4000 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCIE4000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCIE4000 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2000 TX/TX-B",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2000 TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2005 TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX-M",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX-P",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4004 TX/DTX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4004 TX/DTX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD SMART2",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD SMART2 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 3G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G ATT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G VZW VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 3G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G ATT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G VZW VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.4%

Related for CVE-2022-3480