QID 591298

Date Published: 2023-01-20

QID 591298: Phoenix Contact mGuard Denial of Service (DoS) Vulnerability (VDE-2017-001)

AFFECTED PRODUCTS
FL MGUARD CENTERPORT: All versions from 8.0.0 to 8.5.1
FL MGUARD DELTA TX/TX: All versions from 8.0.0 to 8.5.1
FL MGUARD DELTA TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD GT/GT: All versions from 8.0.0 to 8.5.1
FL MGUARD GT/GT VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD PCI4000: All versions from 8.0.0 to 8.5.1
FL MGUARD PCI4000 VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD PCIE4000 VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS: All versions from 8.0.0 to 8.5.1
FL MGUARD RS2000 TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS2005 TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX-P: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX VPN-M: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4004 TX/DTX: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4004 TX/DTX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS VPN ANALOG: All versions from 8.0.0 to 8.5.1
FL MGUARD SMART2: All versions from 8.0.0 to 8.5.1
FL MGUARD SMART2 VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS2000 3G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS2000 4G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS4000 3G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS4000 4G VPN: All versions from 8.0.0 to 8.5.1

QID Detection Logic:
This QID checks for the Vulnerable version of Phoenix Contact mGuard using passive scanning

Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section VDE-2017-001/ for affected packages and patching details.

    Vendor References

    CVEs related to QID 591298

    Software Advisories
    Advisory ID Software Component Link
    VDE-2017-001/ URL Logo cert.vde.com/en/advisories/VDE-2017-001/