QID 590887

Date Published: 2022-06-30

QID 590887: Phoenix Contact Innominate mGuard devices Open Secure Sockets Layer (OpenSSL) Transport Layer Security (TLS) Man-in-the-Middle (MITM) Vulnerability (20140606_001)

Affected products
All Innominate mGuard products running with firmware version 8.0.0, 8.0.1, 8.0.2 or 8.1.0 are affected.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker using a carefully crafted handshake can force the use of weak keying material in OpenSSL SSL/TLS clients and servers. This can be exploited by a Man-In The-Middle (MITM) attack where the attacker can decrypt and modify traffic from the attacked client and server.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to Vendor MITIGATIONS section 20140606_001 for affected packages and patching details.

    CVEs related to QID 590887

    Software Advisories
    Advisory ID Software Component Link
    20140606_001 URL Logo www.phoenixcontact.com/assets/downloads_ed/local_pc/web_dwl_technical_info/innominate_security_advisory_20140606_001_en.pdf