Search

Find a vulnerability

Search criteria

    32 vulnerabilities by phoenixcontact

    CVE-2024-43388 (GCVE-0-2024-43388)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:44 – Updated: 2025-08-22 06:22
    VLAI
    Title
    Phoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devices
    Summary
    A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 13:46 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43388",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T13:46:11.213014Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T14:17:49.005Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Andrea Palanca"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Nozomi Networks Security Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.\u003cbr\u003e\u003cbr\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-22T06:22:30.968Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-039"
            }
          ],
          "source": {
            "advisory": "VDE-2024-039",
            "defect": [
              "CERT@VDE#641656"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devices",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-43388",
        "datePublished": "2024-09-10T08:44:06.550Z",
        "dateReserved": "2024-08-12T08:30:16.360Z",
        "dateUpdated": "2025-08-22T06:22:30.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43387 (GCVE-0-2024-43387)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:43 – Updated: 2024-09-10 14:22
    VLAI
    Title
    Phoenix Contact: Access files due to improper neutralization of special elements in MGUARD devices
    Summary
    A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 14:22 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43387",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T14:22:29.653702Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T14:22:52.652Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Andrea Palanca"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Nozomi Networks Security Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T08:43:54.155Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-039"
            }
          ],
          "source": {
            "advisory": "VDE-2024-039",
            "defect": [
              "CERT@VDE#641656"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: Access files due to improper neutralization of special elements in MGUARD devices",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-43387",
        "datePublished": "2024-09-10T08:43:54.155Z",
        "dateReserved": "2024-08-12T08:30:16.360Z",
        "dateUpdated": "2024-09-10T14:22:52.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43386 (GCVE-0-2024-43386)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:43 – Updated: 2024-09-10 14:25
    VLAI
    Title
    Phoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.
    Summary
    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 14:25 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43386",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T14:25:00.255471Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T14:25:13.169Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Andrea Palanca"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Nozomi Networks Security Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in\u0026nbsp;mGuard devices.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in\u00a0mGuard devices."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T08:43:41.392Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-039"
            }
          ],
          "source": {
            "advisory": "VDE-2024-039",
            "defect": [
              "CERT@VDE#641656"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in\u00a0mGuard devices.",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-43386",
        "datePublished": "2024-09-10T08:43:41.392Z",
        "dateReserved": "2024-08-12T08:30:16.359Z",
        "dateUpdated": "2024-09-10T14:25:13.169Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43385 (GCVE-0-2024-43385)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:43 – Updated: 2024-09-10 14:25
    VLAI
    Title
    Phoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devices
    Summary
    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 14:25 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43385",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T14:25:23.534617Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T14:25:30.320Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Andrea Palanca"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Nozomi Networks Security Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA low privileged remote attacker can trigger the\u0026nbsp;execution of arbitrary OS commands as root due to improper neutralization of special elements in\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ethe variable PROXY_HTTP_PORT in\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003emGuard devices.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A low privileged remote attacker can trigger the\u00a0execution of arbitrary OS commands as root due to improper neutralization of special elements in\u00a0the variable PROXY_HTTP_PORT in\u00a0mGuard devices."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78:Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T08:43:25.556Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-039"
            }
          ],
          "source": {
            "advisory": "VDE-2024-039",
            "defect": [
              "CERT@VDE#641656"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: OS command execution through PROXY_HTTP_PORT in\u00a0mGuard devices",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-43385",
        "datePublished": "2024-09-10T08:43:25.556Z",
        "dateReserved": "2024-08-12T08:30:16.359Z",
        "dateUpdated": "2024-09-10T14:25:30.320Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7699 (GCVE-0-2024-7699)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:42 – Updated: 2024-09-10 14:25
    VLAI
    Title
    Phoenix Contact: OS command execution in MGUARD products
    Summary
    An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 14:25 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7699",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T14:25:49.250812Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T14:25:56.498Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Andrea Palanca"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Nozomi Networks Security Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAn low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T08:42:55.635Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-039"
            }
          ],
          "source": {
            "advisory": "VDE-2024-039",
            "defect": [
              "CERT@VDE#641656"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: OS command execution in MGUARD products",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-7699",
        "datePublished": "2024-09-10T08:42:55.635Z",
        "dateReserved": "2024-08-12T08:30:25.190Z",
        "dateUpdated": "2024-09-10T14:25:56.498Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7734 (GCVE-0-2024-7734)

    Vulnerability from cvelistv5 – Published: 2024-09-10 08:03 – Updated: 2024-09-10 16:00
    VLAI
    Title
    Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
    Summary
    An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 15:54 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT FL MGUARD 2102 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 2105 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCI Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4102 PCIE Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4302 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD 4305 Affected: 0 , < 10.4.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CENTERPORT VPN-1000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD CORE TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD DELTA TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD GT/GT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCI4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD PCIE4000 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX-B Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS2005 TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-M Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX-P Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4000 TX/TX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD RS4004 TX/DTX VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT FL MGUARD SMART2 VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS2000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 3G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G ATT VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN Affected: 0 , < 8.9.3 (semver)
    Create a notification for this product.
    phoenixcontact fl_mguard_smart2_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_gt\/gt_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx-b_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-m_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx-p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact fl_mguard_4305_firmware Affected: 0 , < 10.4.1 (semver)
        cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact tc_mguard_rs4000_4g_vzw_vpn_firmware Affected: 0 , < 8.9.3 (semver)
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_centerport_vpn-1000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_core_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_delta_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_gt\\/gt_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pci4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_pcie4000_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx-b_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs2005_tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-m_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx-p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4000_tx\\/tx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\\/dtx_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_smart2_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_smart2_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2102_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_2105_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pcie_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4102_pci_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4302_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:fl_mguard_4305_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fl_mguard_4305_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "10.4.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs2000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc_mguard_rs4000_4g_vzw_vpn_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "8.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7734",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T15:54:22.823770Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T16:00:45.691Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2102",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 2105",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCI",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4102 PCIE",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4302",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD 4305",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "10.4.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CENTERPORT VPN-1000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD CORE TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD DELTA TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD GT/GT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCI4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD PCIE4000 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX-B",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS2005 TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-M",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX-P",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4000 TX/TX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD RS4004 TX/DTX VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "FL MGUARD SMART2 VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS2000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 3G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G ATT VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TC MGUARD RS4000 4G VZW VPN",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "8.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can\u0026nbsp;exploit the behavior of the\u0026nbsp;pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to\u0026nbsp;blocking of valid IPsec VPN peers.\u003cbr\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can\u00a0exploit the behavior of the\u00a0pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to\u00a0blocking of valid IPsec VPN peers."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T08:03:19.477Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-052"
            }
          ],
          "source": {
            "advisory": "VDE-2024-052",
            "defect": [
              "CERT@VDE#641676"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-7734",
        "datePublished": "2024-09-10T08:03:19.477Z",
        "dateReserved": "2024-08-13T12:52:12.930Z",
        "dateUpdated": "2024-09-10T16:00:45.691Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6788 (GCVE-0-2024-6788)

    Vulnerability from cvelistv5 – Published: 2024-08-13 13:15 – Updated: 2025-08-22 10:24
    VLAI
    Title
    Phoenix Contact: update feature from CHARX controller can be used to reset a low privilege user password
    Summary
    A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-13 16:40 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , < 1.6.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , < 1.6.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , < 1.6.3 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , < 1.6.3 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , < 1.6.3 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "1.6.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6788",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-13T16:40:42.748470Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-13T16:50:38.588Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "1.6.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "1.6.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "1.6.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "1.6.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "McCaulay Hudson"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Alexander Plaskett"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "NCC Group"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user \u201cuser-app\u201d to the default password.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user \u201cuser-app\u201d to the default password."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1392",
                  "description": "CWE-1392 Use of Default Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-22T10:24:58.187Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-022"
            }
          ],
          "source": {
            "advisory": "VDE-2024-022",
            "defect": [
              "CERT@VDE#641622"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: update feature from CHARX controller can be used to reset a low privilege user password",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-6788",
        "datePublished": "2024-08-13T13:15:03.120Z",
        "dateReserved": "2024-07-16T12:18:00.312Z",
        "dateUpdated": "2025-08-22T10:24:58.187Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3913 (GCVE-0-2024-3913)

    Vulnerability from cvelistv5 – Published: 2024-08-13 12:30 – Updated: 2025-01-29 06:04
    VLAI
    Title
    Phoenix Contact: Start sequence allows attack during the boot process
    Summary
    An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-13 13:48 UTC
    CWE
    • CWE-552 - Files or Directories Accessible to External Parties
    References
    Impacted products
    Vendor Product Version
    Phoenix Contact CHARX SEC-3000 (1139022) Affected: 0.0.0 , < 1.7.0 (semver)
    Create a notification for this product.
    Phoenix Contact CHARX SEC-3050 (1139018) Affected: 0.0.0 , < 1.7.0 (semver)
    Create a notification for this product.
    Phoenix Contact CHARX SEC-3100 (1139012) Affected: 0.0.0 , < 1.7.0 (semver)
    Create a notification for this product.
    Phoenix Contact CHARX SEC-3150 (1139012) Affected: 0.0.0 , < 1.7.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0.0.0 , < 1.7.0 (semver)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0.0.0 , < 1.7.0 (semver)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0.0.0 , < 1.7.0 (semver)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0.0.0 , < 1.7.0 (semver)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "1.7.0",
                    "status": "affected",
                    "version": "0.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "1.7.0",
                    "status": "affected",
                    "version": "0.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "1.7.0",
                    "status": "affected",
                    "version": "0.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "1.7.0",
                    "status": "affected",
                    "version": "0.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3913",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-13T13:48:51.878463Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-13T13:56:57.855Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000 (1139022)",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.0",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050 (1139018)",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.0",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100 (1139012)",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.0",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150 (1139012)",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.0",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Alex Olson, \"gadha\""
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAn unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552 Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-29T06:04:51.452Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-022"
            }
          ],
          "source": {
            "advisory": "VDE-2024-022",
            "defect": [
              "CERT@VDE#641622"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Phoenix Contact: Start sequence allows attack during the boot process",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-3913",
        "datePublished": "2024-08-13T12:30:33.535Z",
        "dateReserved": "2024-04-17T07:09:02.592Z",
        "dateUpdated": "2025-01-29T06:04:51.452Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28137 (GCVE-0-2024-28137)

    Vulnerability from cvelistv5 – Published: 2024-05-14 08:10 – Updated: 2024-08-02 00:48
    VLAI
    Title
    PHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series
    Summary
    A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-14 14:15 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28137",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-14T14:15:00.603552Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T15:25:47.839Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:49.163Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Todd Manning"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003e\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003c/p\u003e\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003eA local attacker with low privileges can\u0026nbsp;perform a privilege escalation with an init script due to a  TOCTOU vulnerability.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\n\t\t\t\t\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e\n\t\n"
                }
              ],
              "value": "\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\t\t\t\t\t\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\n\n\n\t\t\t\n\t\t\t\t\n\t\t\t\t\tA local attacker with low privileges can\u00a0perform a privilege escalation with an init script due to a  TOCTOU vulnerability.\n\n\n\n\n\n\n\n\n\n\n\t\t\t\t\n\n\n\t\t\t\n\n\n\t\t\n\n\n\t\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-03T11:48:50.771Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
            }
          ],
          "source": {
            "advisory": "VDE-2024-019",
            "defect": [
              "CERT@VDE#64664"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: privilege escalation due to a  TOCTOU vulnerability in the CHARX Series ",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-28137",
        "datePublished": "2024-05-14T08:10:06.014Z",
        "dateReserved": "2024-03-05T08:10:25.697Z",
        "dateUpdated": "2024-08-02T00:48:49.163Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28136 (GCVE-0-2024-28136)

    Vulnerability from cvelistv5 – Published: 2024-05-14 08:09 – Updated: 2025-01-24 06:33
    VLAI
    Title
    PHOENIX CONTACT: command injection gains root privileges using the OCPP remote service
    Summary
    A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-14 13:43 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-14T13:43:24.083625Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T15:25:25.119Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:49.214Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "@ByteInsight"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003e\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003c/p\u003e\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003eA local attacker with low privileges can \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euse a command injection vulnerability to \u003c/span\u003egain root\nprivileges due to improper input validation using the OCPP Remote service.\u003cbr\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e"
                }
              ],
              "value": "A local attacker with low privileges can use a command injection vulnerability to gain root\nprivileges due to improper input validation using the OCPP Remote service."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-24T06:33:52.412Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
            }
          ],
          "source": {
            "advisory": "VDE-2024-019",
            "defect": [
              "CERT@VDE#64664"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: command injection gains root privileges using the OCPP remote service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-28136",
        "datePublished": "2024-05-14T08:09:52.725Z",
        "dateReserved": "2024-03-05T08:10:25.697Z",
        "dateUpdated": "2025-01-24T06:33:52.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28135 (GCVE-0-2024-28135)

    Vulnerability from cvelistv5 – Published: 2024-05-14 08:09 – Updated: 2025-01-24 06:35
    VLAI
    Title
    PHOENIX CONTACT: command injection vulnerability in the API of the CHARX Series
    Summary
    A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-14 15:03 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28135",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-14T15:03:58.528873Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T15:24:54.870Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:49.242Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003e\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003c/p\u003e\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003eA low privileged remote attacker can use\u0026nbsp;a command injection vulnerability in the API which performs\nremote code execution \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eas the \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euser-app\u0026nbsp;\u003c/span\u003euser\u0026nbsp;\u003c/span\u003edue to improper input validation. The confidentiality is partly affected.\u003cbr\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\n\t\t\t\t\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e"
                }
              ],
              "value": "A low privileged remote attacker can use\u00a0a command injection vulnerability in the API which performs\nremote code execution as the user-app\u00a0user\u00a0due to improper input validation. The confidentiality is partly affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-24T06:35:03.912Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
            }
          ],
          "source": {
            "advisory": "VDE-2024-019",
            "defect": [
              "CERT@VDE#64664"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: command injection vulnerability in the API of the CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-28135",
        "datePublished": "2024-05-14T08:09:39.703Z",
        "dateReserved": "2024-03-05T08:10:25.697Z",
        "dateUpdated": "2025-01-24T06:35:03.912Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28134 (GCVE-0-2024-28134)

    Vulnerability from cvelistv5 – Published: 2024-05-14 08:09 – Updated: 2024-08-02 00:48
    VLAI
    Title
    PHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series
    Summary
    An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-14 14:17 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28134",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-14T14:17:34.394686Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T15:24:34.250Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:49.289Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003e\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003c/p\u003e\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003eAn unauthenticated remote attacker can extract a session token with a MitM attack and gain\u0026nbsp;web-based\nmanagement access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNo additional user interaction is required.\u0026nbsp;\u003c/span\u003eThe access is limited as only non-sensitive information can be obtained but the availability can be seriously affected.\u0026nbsp;\u003cbr\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e\n\t\n"
                }
              ],
              "value": "\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\t\t\t\t\t\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\n\n\n\t\t\t\n\t\t\t\t\n\t\t\t\t\tAn unauthenticated remote attacker can extract a session token with a MitM attack and gain\u00a0web-based\nmanagement access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required.\u00a0The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected.\u00a0\n\n\n\n\n\n\n\n\n\n\n\n\t\t\t\n\n\n\t\t\n\n\n\t\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319 Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-03T11:48:10.617Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
            }
          ],
          "source": {
            "advisory": "VDE-2024-019",
            "defect": [
              "CERT@VDE#64664"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series ",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-28134",
        "datePublished": "2024-05-14T08:09:24.900Z",
        "dateReserved": "2024-03-05T08:10:25.696Z",
        "dateUpdated": "2024-08-02T00:48:49.289Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28133 (GCVE-0-2024-28133)

    Vulnerability from cvelistv5 – Published: 2024-05-14 08:09 – Updated: 2024-08-02 00:48
    VLAI
    Title
    PHOENIX CONTACT: Privilege escalation in CHARX Series
    Summary
    A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-14 14:19 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.1 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.1 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28133",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-14T14:19:05.526123Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T15:24:12.263Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:49.201Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Trend Micro\u0027s Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) "
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\u003cdiv\u003e\n\t\t\t\u003cdiv\u003e\n\t\t\t\t\u003cdiv\u003e\n\t\t\t\t\t\u003cp\u003eA local low privileged attacker can use \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ean untrusted search path in a\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eCHARX system utility\u003c/span\u003e to gain\u003c/span\u003e\u0026nbsp;root\nprivileges.\u0026nbsp;\u003cbr\u003e\u003c/p\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\n\t\t\t\t\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e\n\t\n\u003cp\u003e\u003c/p\u003e\n\t\t\t\t\u003c/div\u003e\n\t\t\t\u003c/div\u003e\n\t\t\u003c/div\u003e\n\t\n"
                }
              ],
              "value": "\n\t\n\t\t\n\t\t\n\t\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\t\t\t\t\tA local low privileged attacker can use an untrusted search path in a\u00a0CHARX system utility to gain\u00a0root\nprivileges.\u00a0\n\n\n\n\t\t\t\t\n\n\n\t\t\t\n\n\n\t\t\n\n\n\t\n\n\n\n\t\t\t\t\n\n\n\t\t\t\n\n\n\t\t\n\n\n\t\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-426",
                  "description": "CWE-426 Untrusted Search Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-03T11:47:59.462Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-019"
            }
          ],
          "source": {
            "advisory": "VDE-2024-019",
            "defect": [
              "CERT@VDE#64664"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Privilege escalation in CHARX Series ",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-28133",
        "datePublished": "2024-05-14T08:09:11.136Z",
        "dateReserved": "2024-03-05T08:10:25.696Z",
        "dateUpdated": "2024-08-02T00:48:49.201Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-26288 (GCVE-0-2024-26288)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:13 – Updated: 2024-08-02 00:07
    VLAI
    Title
    PHOENIX CONTACT: Lack of SSL support in CHARX Series
    Summary
    An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 13:09 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26288",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T13:09:55.743451Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:50:37.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:07:19.074Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Chris Anastasio "
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Fabius Watson"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected."
                }
              ],
              "value": "An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319 Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:13:05.195Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Lack of SSL support in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-26288",
        "datePublished": "2024-03-12T08:13:05.195Z",
        "dateReserved": "2024-02-16T13:45:24.697Z",
        "dateUpdated": "2024-08-02T00:07:19.074Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-26004 (GCVE-0-2024-26004)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:12 – Updated: 2024-08-01 23:52
    VLAI
    Title
    PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX Series
    Summary
    An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 15:53 UTC
    CWE
    • CWE-824 - Access of Uninitialized Pointer
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26004",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T15:53:30.751365Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:52:12.052Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.500Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Jack Dates"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RET2 Systems"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer\u0026nbsp;which may prevent or disrupt the charging functionality. "
                }
              ],
              "value": "An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer\u00a0which may prevent or disrupt the charging functionality. "
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-824",
                  "description": "CWE-824 Access of Uninitialized Pointer",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:12:38.367Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer\u00a0in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-26004",
        "datePublished": "2024-03-12T08:12:38.367Z",
        "dateReserved": "2024-02-14T08:22:26.365Z",
        "dateUpdated": "2024-08-01T23:52:06.500Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-26003 (GCVE-0-2024-26003)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:12 – Updated: 2024-08-01 23:52
    VLAI
    Title
    PHOENIX CONTACT: DoS of the control agent in CHARX Series
    Summary
    An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 13:17 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26003",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T13:17:04.404042Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:49:35.376Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.448Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Jack Dates"
            },
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RET2 Systems"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.\u0026nbsp;"
                }
              ],
              "value": "An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.\u00a0"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:12:26.754Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: DoS of the control agent in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-26003",
        "datePublished": "2024-03-12T08:12:26.754Z",
        "dateReserved": "2024-02-14T08:22:26.365Z",
        "dateUpdated": "2024-08-01T23:52:06.448Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-26002 (GCVE-0-2024-26002)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:12 – Updated: 2024-08-01 23:52
    VLAI
    Title
    PHOENIX CONTACT: File ownership manipulation in CHARX Series
    Summary
    An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 18:45 UTC
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26002",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T18:45:35.557638Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:51:40.778Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.437Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Peter Geissler"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rick De Jager"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Carlo Meijer"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files."
                }
              ],
              "value": "An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:12:13.841Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: File ownership manipulation in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-26002",
        "datePublished": "2024-03-12T08:12:13.841Z",
        "dateReserved": "2024-02-14T08:22:26.365Z",
        "dateUpdated": "2024-08-01T23:52:06.437Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-26001 (GCVE-0-2024-26001)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:12 – Updated: 2025-01-24 06:36
    VLAI
    Title
    PHOENIX CONTACT: Out of bounds write only memory access
    Summary
    An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 18:26 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26001",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T18:26:16.012872Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:52:36.152Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.443Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Peter Geissler"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rick De Jager"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Carlo Meijer"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can write\u0026nbsp;memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. \u003cbr\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can write\u00a0memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-24T06:36:20.776Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Out of bounds write only memory access",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-26001",
        "datePublished": "2024-03-12T08:12:03.535Z",
        "dateReserved": "2024-02-14T08:22:26.365Z",
        "dateUpdated": "2025-01-24T06:36:20.776Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25998 (GCVE-0-2024-25998)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:11 – Updated: 2025-01-24 06:45
    VLAI
    Title
    PHOENIX CONTACT: Command injection in the OCPP Service
    Summary
    An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-28 01:53 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25998",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-28T01:53:23.436340Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:53:26.535Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.366Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Chris Anastasio"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Fabius Watson"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can perform a command injection\u0026nbsp;in the OCPP\u0026nbsp;Service with limited privileges due to improper input validation.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can perform a command injection\u00a0in the OCPP\u00a0Service with limited privileges due to improper input validation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-24T06:45:26.082Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Command injection in the OCPP Service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-25998",
        "datePublished": "2024-03-12T08:11:31.787Z",
        "dateReserved": "2024-02-14T08:22:26.364Z",
        "dateUpdated": "2025-01-24T06:45:26.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25997 (GCVE-0-2024-25997)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:11 – Updated: 2024-08-01 23:52
    VLAI
    Title
    PHOENIX CONTACT: Log injection in CHARX Series
    Summary
    An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 13:12 UTC
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25997",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T13:12:43.976071Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:54:13.276Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.435Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Chris Anastasio"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Fabius Watson"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can perform a log injection due to improper input validation. \u003cspan style=\"background-color: var(--wht);\"\u003eOnly a certain log file is affected.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:11:19.909Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Log injection in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-25997",
        "datePublished": "2024-03-12T08:11:19.909Z",
        "dateReserved": "2024-02-14T08:22:26.364Z",
        "dateUpdated": "2024-08-01T23:52:06.435Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25996 (GCVE-0-2024-25996)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:11 – Updated: 2024-08-01 23:52
    VLAI
    Title
    PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series
    Summary
    An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 16:19 UTC
    CWE
    • CWE-346 - Origin Validation Error
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25996",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T16:19:14.179453Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:54:36.920Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.388Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Tobias Scharnowski of fuzzware.io"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Felix Buchmann of fuzzware.io"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The a\u003cspan style=\"background-color: var(--wht);\"\u003eccess is limited to the service user.\u003c/span\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "CWE-346 Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T08:11:08.905Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series ",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-25996",
        "datePublished": "2024-03-12T08:11:08.905Z",
        "dateReserved": "2024-02-14T08:22:26.364Z",
        "dateUpdated": "2024-08-01T23:52:06.388Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25995 (GCVE-0-2024-25995)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:10 – Updated: 2025-01-30 10:48
    VLAI
    Title
    PHOENIX CONTACT: Remote code execution in CHARX Series
    Summary
    An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 15:59 UTC
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25995",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T15:59:09.576419Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:49:44.942Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.490Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Alex Plaskett of NCC Group"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "McClaulay Hudson of NCC Group"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation."
                }
              ],
              "value": "An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-30T10:48:21.911Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-856/"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Remote code execution in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-25995",
        "datePublished": "2024-03-12T08:10:58.302Z",
        "dateReserved": "2024-02-14T08:22:26.364Z",
        "dateUpdated": "2025-01-30T10:48:21.911Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25994 (GCVE-0-2024-25994)

    Vulnerability from cvelistv5 – Published: 2024-03-12 08:10 – Updated: 2025-01-24 06:47
    VLAI
    Title
    PHOENIX CONTACT: Unintended script file upload in CHARX Series
    Summary
    An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 15:53 UTC
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT CHARX SEC-3000 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3050 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3100 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    PHOENIX CONTACT CHARX SEC-3150 Affected: 0 , ≤ 1.5.0 (semver)
    Create a notification for this product.
    phoenixcontact charx_sec_3000 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3050 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3100 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact charx_sec_3150 Affected: 0 , ≤ 1.5.0 (custom)
        cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3000",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3050:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3050",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3100:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3100",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:phoenixcontact:charx_sec_3150:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "charx_sec_3150",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "1.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25994",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T15:53:04.268021Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:55:02.554Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:52:06.554Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThanOrEqual": "1.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Alex Plaskett of NCC Group"
            },
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "McClaulay Hudson of NCC Group"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation.\u0026nbsp;\u003cspan style=\"background-color: var(--wht);\"\u003eThe upload destination is fixed and is write only.\u003c/span\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation.\u00a0The upload destination is fixed and is write only."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-24T06:47:39.754Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-011"
            }
          ],
          "source": {
            "advisory": "VDE-2024-011",
            "defect": [
              "CERT@VDE#64650"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "PHOENIX CONTACT: Unintended script file upload in CHARX Series",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2024-25994",
        "datePublished": "2024-03-12T08:10:46.012Z",
        "dateReserved": "2024-02-14T08:22:26.364Z",
        "dateUpdated": "2025-01-24T06:47:39.754Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-37863 (GCVE-0-2023-37863)

    Vulnerability from cvelistv5 – Published: 2023-08-09 06:36 – Updated: 2024-10-10 18:24
    VLAI
    Title
    PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 17:58 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6070-wvps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6101-wxps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6121-wxps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6156-whps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6185-whps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps_firmware Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:o:phoenixcontact:wp_6215-whps_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:23:27.634Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6070-wvps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6070-wvps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6101-wxps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6101-wxps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6121-wxps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6121-wxps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6156-whps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6156-whps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6185-whps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6185-whps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:phoenixcontact:wp_6215-whps_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6215-whps_firmware",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-37863",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T17:58:39.456950Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T18:24:06.844Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10\u0026nbsp;a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10\u00a0a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-09T06:36:28.150Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-37863",
        "datePublished": "2023-08-09T06:36:28.150Z",
        "dateReserved": "2023-07-10T07:53:04.116Z",
        "dateUpdated": "2024-10-10T18:24:06.844Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-37864 (GCVE-0-2023-37864)

    Vulnerability from cvelistv5 – Published: 2023-08-09 06:35 – Updated: 2024-10-10 17:34
    VLAI
    Title
    PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity check
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 17:27 UTC
    CWE
    • CWE-494 - Download of Code Without Integrity Check
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:23:27.683Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-37864",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T17:27:32.978485Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T17:34:41.503Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges\u0026nbsp;may use an a special SNMP request to gain full access to the device."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges\u00a0may use an a special SNMP request to gain full access to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-494",
                  "description": "CWE-494 Download of Code Without Integrity Check",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-09T06:35:48.425Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity check",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-37864",
        "datePublished": "2023-08-09T06:35:48.425Z",
        "dateReserved": "2023-07-10T07:53:04.116Z",
        "dateUpdated": "2024-10-10T17:34:41.503Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-37862 (GCVE-0-2023-37862)

    Vulnerability from cvelistv5 – Published: 2023-08-09 06:35 – Updated: 2024-10-10 17:43
    VLAI
    Title
    PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 17:36 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:23:27.744Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-37862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T17:36:26.292093Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T17:43:31.957Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-09T06:35:14.704Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-37862",
        "datePublished": "2023-08-09T06:35:14.704Z",
        "dateReserved": "2023-07-10T07:53:04.115Z",
        "dateUpdated": "2024-10-10T17:43:31.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-37860 (GCVE-0-2023-37860)

    Vulnerability from cvelistv5 – Published: 2023-08-09 06:34 – Updated: 2024-10-10 17:50
    VLAI
    Title
    PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 17:44 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:23:27.590Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-37860",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T17:44:46.862605Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T17:50:45.168Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.\u003cbr\u003e"
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-25T06:32:01.495Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-37860",
        "datePublished": "2023-08-09T06:34:56.332Z",
        "dateReserved": "2023-07-10T07:53:04.115Z",
        "dateUpdated": "2024-10-10T17:50:45.168Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-37861 (GCVE-0-2023-37861)

    Vulnerability from cvelistv5 – Published: 2023-08-09 06:34 – Updated: 2024-10-10 17:59
    VLAI
    Title
    PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 17:52 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:23:27.639Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-37861",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T17:52:10.296158Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T17:59:20.403Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-09T06:34:36.113Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-37861",
        "datePublished": "2023-08-09T06:34:36.113Z",
        "dateReserved": "2023-07-10T07:53:04.115Z",
        "dateUpdated": "2024-10-10T17:59:20.403Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-3570 (GCVE-0-2023-3570)

    Vulnerability from cvelistv5 – Published: 2023-08-08 06:52 – Updated: 2024-10-15 19:13
    VLAI
    Title
    PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 19:09 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:01:55.948Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-3570",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T19:09:27.526246Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T19:13:29.756Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-25T06:07:25.366Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-3570",
        "datePublished": "2023-08-08T06:52:57.641Z",
        "dateReserved": "2023-07-10T07:53:11.063Z",
        "dateUpdated": "2024-10-15T19:13:29.756Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-3572 (GCVE-0-2023-3572)

    Vulnerability from cvelistv5 – Published: 2023-08-08 06:52 – Updated: 2024-10-15 19:18
    VLAI
    Title
    PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels
    Summary
    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 19:14 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    PHOENIX CONTACT WP 6070-WVPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6101-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6121-WXPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6156-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6185-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    PHOENIX CONTACT WP 6215-WHPS Affected: 0 , < 4.0.10 (semver)
    Create a notification for this product.
    phoenixcontact wp_6070-wvps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6101-wxps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6121-wxps Affected: 0 , ≤ 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6156-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6185-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    phoenixcontact wp_6215-whps Affected: 0 , < 4.0.10 (semver)
        cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-08 06:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:01:55.922Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6070-wvps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6101-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6121-wxps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThanOrEqual": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6156-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6185-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "wp_6215-whps",
                "vendor": "phoenixcontact",
                "versions": [
                  {
                    "lessThan": "4.0.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-3572",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T19:14:50.910247Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T19:18:16.801Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP 6070-WVPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6101-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6121-WXPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6156-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6185-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP 6215-WHPS",
              "vendor": "PHOENIX CONTACT",
              "versions": [
                {
                  "lessThan": "4.0.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Gabriele Quagliarella from Nozomi Networks Labs"
            }
          ],
          "datePublic": "2023-08-08T06:45:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device."
                }
              ],
              "value": "In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-08T08:12:15.705Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2023-018/"
            }
          ],
          "source": {
            "advisory": "VDE-2023-018",
            "defect": [
              "CERT@VDE#64468"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-3572",
        "datePublished": "2023-08-08T06:52:29.820Z",
        "dateReserved": "2023-07-10T07:53:13.476Z",
        "dateUpdated": "2024-10-15T19:18:16.801Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }