CVE-2020-12523

On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_att_vpn:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_3g_vpn:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vpn:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:59

Type Values Removed Values Added
References () https://cert.vde.com/en-us/advisories/vde-2020-046 - Third Party Advisory () https://cert.vde.com/en-us/advisories/vde-2020-046 - Third Party Advisory
CVSS v2 : 6.4
v3 : 9.1
v2 : 6.4
v3 : 5.4

Information

Published : 2020-12-17 23:15

Updated : 2024-11-21 04:59


NVD link : CVE-2020-12523

Mitre link : CVE-2020-12523

CVE.ORG link : CVE-2020-12523


JSON object : View

Products Affected

phoenixcontact

  • innominate_mguard_rs4000_4tx\/tx_firmware
  • tc_mguard_rs4000_4g_vpn_firmware
  • fl_mguard_rs4004_tx\/dtx_vpn
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware
  • tc_mguard_rs4000_4g_att_vpn
  • fl_mguard_rs4004_tx\/dtx
  • innominate_mguard_rs4000_4tx\/tx
  • fl_mguard_rs4004_tx\/dtx_vpn_firmware
  • tc_mguard_rs4000_3g_vpn
  • innominate_mguard_rs4000_4tx\/tx_vpn
  • innominate_mguard_rs4000_4tx\/tx_vpn_firmware
  • fl_mguard_rs4004_tx\/dtx_firmware
  • tc_mguard_rs4000_4g_vzw_vpn
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn
  • tc_mguard_rs4000_4g_vpn
  • tc_mguard_rs4000_4g_att_vpn_firmware
  • tc_mguard_rs4000_3g_vpn_firmware
  • tc_mguard_rs4000_4g_vzw_vpn_firmware
CWE
CWE-909

Missing Initialization of Resource