CVE-2018-5441
Summary
| CVE | CVE-2018-5441 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-30 20:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Phoenix Contact mGuard CVE-2018-5441 Local Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| PHOENIX CONTACT mGuard | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| PHOENIX CONTACT Advisory for mGuard products — English (USA) | CONFIRM | cert.vde.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590577 PHOENIX CONTACT mGuard Improper Validation of Integrity Check Value Vulnerability (ICSA-18-030-01)