QID 591298
Date Published: 2023-01-20
QID 591298: Phoenix Contact mGuard Denial of Service (DoS) Vulnerability (VDE-2017-001)
AFFECTED PRODUCTS
FL MGUARD CENTERPORT: All versions from 8.0.0 to 8.5.1
FL MGUARD DELTA TX/TX: All versions from 8.0.0 to 8.5.1
FL MGUARD DELTA TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD GT/GT: All versions from 8.0.0 to 8.5.1
FL MGUARD GT/GT VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD PCI4000: All versions from 8.0.0 to 8.5.1
FL MGUARD PCI4000 VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD PCIE4000 VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS: All versions from 8.0.0 to 8.5.1
FL MGUARD RS2000 TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS2005 TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX-P: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4000 TX/TX VPN-M: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4004 TX/DTX: All versions from 8.0.0 to 8.5.1
FL MGUARD RS4004 TX/DTX VPN: All versions from 8.0.0 to 8.5.1
FL MGUARD RS VPN ANALOG: All versions from 8.0.0 to 8.5.1
FL MGUARD SMART2: All versions from 8.0.0 to 8.5.1
FL MGUARD SMART2 VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS2000 3G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS2000 4G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS4000 3G VPN: All versions from 8.0.0 to 8.5.1
TC MGUARD RS4000 4G VPN: All versions from 8.0.0 to 8.5.1
QID Detection Logic:
This QID checks for the Vulnerable version of Phoenix Contact mGuard using passive scanning
Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
Customers are advised to refer to CERT MITIGATIONS section VDE-2017-001/ for affected packages and patching details.
- VDE-2017-001 -
cert.vde.com/en/advisories/VDE-2017-001/
CVEs related to QID 591298
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VDE-2017-001/ |
|