{"api_version":"1","generated_at":"2026-07-23T15:20:25+00:00","cve":"CVE-2017-7937","urls":{"html":"https://cve.report/CVE-2017-7937","api":"https://cve.report/api/cve/CVE-2017-7937.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7937","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7937"},"summary":{"title":"CVE-2017-7937","description":"An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-05-19 03:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-287","CWE-287 CWE-287"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"PHOENIX CONTACT mGuard | CISA","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7937","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7937","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Phoenix Contact GmbH mGuard","version":"affected Phoenix Contact GmbH mGuard","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7937","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"phoenix_contact_gmbh","cpe5":"mguard","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7937","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"phoenix_contact_gmbh","cpe5":"mguard_firmware","cpe6":"8.4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-7937","qid":"590569","title":"PHOENIX CONTACT mGuard Multiple Vulnerabilities (ICSA-17-131-01)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:19:29.218Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Phoenix Contact GmbH mGuard","vendor":"n/a","versions":[{"status":"affected","version":"Phoenix Contact GmbH mGuard"}]}],"datePublic":"2017-05-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-287","description":"CWE-287","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-05-19T02:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-7937","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Phoenix Contact GmbH mGuard","version":{"version_data":[{"version_value":"Phoenix Contact GmbH mGuard"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-131-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-7937","datePublished":"2017-05-19T02:43:00.000Z","dateReserved":"2017-04-18T00:00:00.000Z","dateUpdated":"2024-08-05T16:19:29.218Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-19 03:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-287","CWE-287 CWE-287"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.3.0:*:*:*:*:*:*:*","matchCriteriaId":"116FA86C-7A05-4B2C-8148-6FE371E60D70"},{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.3.1:*:*:*:*:*:*:*","matchCriteriaId":"236DEF3C-0F0F-467B-9EEB-276092938DAF"},{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.3.2:*:*:*:*:*:*:*","matchCriteriaId":"A6A1E205-BB61-47BE-A903-0F122D2D732A"},{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.4.0:*:*:*:*:*:*:*","matchCriteriaId":"BCB742B0-8E3E-4110-87A9-D40360743A42"},{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.4.1:*:*:*:*:*:*:*","matchCriteriaId":"582782AB-3CBC-4EB6-B271-4AA270F87CB1"},{"vulnerable":true,"criteria":"cpe:2.3:o:phoenix_contact_gmbh:mguard_firmware:8.4.2:*:*:*:*:*:*:*","matchCriteriaId":"3625B7F5-0170-4269-97A3-F3ABF147F803"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:phoenix_contact_gmbh:mguard:-:*:*:*:*:*:*:*","matchCriteriaId":"418AA18B-BB7E-4C77-BF5C-F1CB320B643B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7937","Ordinal":"1","Title":"CVE-2017-7937","CVE":"CVE-2017-7937","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7937","Ordinal":"1","NoteData":"An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.","Type":"Description","Title":"CVE-2017-7937"},{"CveYear":"2017","CveId":"7937","Ordinal":"2","NoteData":"2017-05-18","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7937","Ordinal":"3","NoteData":"2017-05-18","Type":"Other","Title":"Modified"}]}}}