QID 591336

Date Published: 2023-04-03

QID 591336: Phoenix Contact mGuard Missing Initialization of Resource Vulnerability (VDE-2020-046)

AFFECTED PRODUCTS
FL MGUARD RS4004 TX/DTX: All version prior to 8.8.3
FL MGUARD RS4004 TX/DTX VPN: All version prior to 8.8.3
TC MGUARD RS4000 3G VPN: All version prior to 8.8.3
TC MGUARD RS4000 4G ATT VPN: All version prior to 8.8.3
TC MGUARD RS4000 4G VPN: All version prior to 8.8.3
TC MGUARD RS4000 4G VZW VPN: All version prior to 8.8.3

QID Detection Logic:
This QID checks for the Vulnerable version of Omron NJ/NX-series Machine Automation Controllers using passive scanning

For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource (CWE-909).

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section VDE-2020-046 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591336

    Software Advisories
    Advisory ID Software Component Link
    VDE-2020-046 URL Logo cert.vde.com/en/advisories/VDE-2020-046/