QID 590886

Date Published: 2022-06-30

QID 590886: Phoenix Contact Innominate mGuard devices Vulnerability (20141217_002)

Affected products
All Innominate mGuard devices running with firmware version 6.1.0 up to firmware version 8.1.3 are affected if listening for TCP encapsulated connections is enabled. The firmware versions 8.1.4 and higher are not affected. The mGuard firmware 7.6.6 patch release also fixes this issue.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The mGuard TCP encapsulation of IPSec traffic uses an OpenVPN connection to tunnel IPSec packets. Because of CVE-2014-8104 an attacker may interrupt such TCP encapsulated connections.

  • CVSS V3 rated as Medium - 5.7 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to Vendor MITIGATIONS section 20141217_002 for affected packages and patching details.

    CVEs related to QID 590886

    Software Advisories
    Advisory ID Software Component Link
    20141217_002 URL Logo www.phoenixcontact.com/assets/downloads_ed/local_pc/web_dwl_technical_info/innominate_security_advisory_20141217_002_en.pdf