Vulnerabilities
Vulnerable Software
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
CVSS Score
8.8
EPSS Score
0.004
Published
2024-09-10
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-09-10
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
CVSS Score
5.3
EPSS Score
0.0
Published
2023-06-13
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-11-15
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
CVSS Score
5.4
EPSS Score
0.004
Published
2020-12-17


Contact Us

Shodan ® - All rights reserved