{"api_version":"1","generated_at":"2026-04-23T02:36:28+00:00","cve":"CVE-2021-34579","urls":{"html":"https://cve.report/CVE-2021-34579","api":"https://cve.report/api/cve/CVE-2021-34579.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-34579","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-34579"},"summary":{"title":"CVE-2021-34579","description":"In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.","state":"PUBLIC","assigner":"info@cert.vde.com","published_at":"2022-11-09 17:15:00","updated_at":"2022-11-15 16:28:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://cert.vde.com/en/advisories/VDE-2021-035/","name":"https://cert.vde.com/en/advisories/VDE-2021-035/","refsource":"MISC","tags":[],"title":"VDE-2021-035 | CERT@VDE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-34579","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-34579","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"34579","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phoenixcontact","cpe5":"fl_mguard_dm","cpe6":"1.12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"34579","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phoenixcontact","cpe5":"fl_mguard_dm","cpe6":"1.13.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-34579","qid":"591246","title":"Phoenix Contact FL MGUARD DM Improper Privilege Management Vulnerability (VDE-2021-035)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2021-34579","ASSIGNER":"info@cert.vde.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-269 Improper Privilege Management","cweId":"CWE-269"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"PHOENIX CONTACT","product":{"product_data":[{"product_name":"FL MGUARD DM (2981974)","version":{"version_data":[{"version_value":"1.12.0","version_affected":"="},{"version_value":"1.13.0","version_affected":"="}]}}]}}]}},"references":{"reference_data":[{"url":"https://cert.vde.com/en/advisories/VDE-2021-035/","refsource":"MISC","name":"https://cert.vde.com/en/advisories/VDE-2021-035/"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"advisory":"VDE-2021-035","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2022-11-09 17:15:00","lastModifiedDate":"2022-11-15 16:28:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:phoenixcontact:fl_mguard_dm:1.12.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:phoenixcontact:fl_mguard_dm:1.13.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"34579","Ordinal":"210044","Title":"CVE-2021-34579","CVE":"CVE-2021-34579","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"34579","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}