QID 590887
Date Published: 2022-06-30
QID 590887: Phoenix Contact Innominate mGuard devices Open Secure Sockets Layer (OpenSSL) Transport Layer Security (TLS) Man-in-the-Middle (MITM) Vulnerability (20140606_001)
Affected products
All Innominate mGuard products running with firmware version 8.0.0, 8.0.1, 8.0.2 or 8.1.0 are affected.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An attacker using a carefully crafted handshake can force the use of weak keying material in OpenSSL SSL/TLS clients and servers. This can be exploited by a Man-In The-Middle (MITM) attack where the attacker can decrypt and modify traffic from the attacked client and server.
Solution
Customers are advised to refer to Vendor MITIGATIONS section 20140606_001 for affected packages and patching details.
Vendor References
CVEs related to QID 590887
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20140606_001 |
|