Lucene search

K
cvelistCERTVDECVELIST:CVE-2022-3480
HistoryNov 15, 2022 - 10:58 a.m.

CVE-2022-3480 Denial-of-Service vulnerability in PHOENIX CONTACT mGuard product family

2022-11-1510:58:25
CWE-770
CERTVDE
www.cve.org
denial of service
phoenix contact
mguard
vulnerability
unauthenticated attacker
https connections
firewall limits
version 8.9.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

56.4%

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CENTERPORT",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CENTERPORT VPN-1000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CORE TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD CORE TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD DELTA TX/TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD DELTA TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD GT/GT",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD GT/GT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCI4000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCI4000 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCIE4000",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD PCIE4000 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2000 TX/TX-B",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2000 TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS2005 TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX-M",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX-P",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4000 TX/TX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4004 TX/DTX",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD RS4004 TX/DTX VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD SMART2",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "FL MGUARD SMART2 VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 3G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G ATT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS2000 4G VZW VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 3G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G ATT VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "TC MGUARD RS4000 4G VZW VPN",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThan": "8.9.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

56.4%

Related for CVELIST:CVE-2022-3480