CVE-2020-12523

On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2020-046 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_att_vpn:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_3g_vpn:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vpn:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn:-:*:*:*:*:*:*:*

Information

Published : 2020-12-17 15:15

Updated : 2020-12-21 06:16


NVD link : CVE-2020-12523

Mitre link : CVE-2020-12523


JSON object : View

CWE
CWE-909

Missing Initialization of Resource

Advertisement

dedicated server usa

Products Affected

phoenixcontact

  • tc_mguard_rs4000_4g_vpn_firmware
  • tc_mguard_rs4000_4g_vzw_vpn_firmware
  • tc_mguard_rs4000_4g_vpn
  • tc_mguard_rs4000_4g_att_vpn_firmware
  • tc_mguard_rs4000_3g_vpn
  • innominate_mguard_rs4000_4tx\/tx
  • innominate_mguard_rs4000_4tx\/tx_vpn
  • fl_mguard_rs4004_tx\/dtx_firmware
  • tc_mguard_rs4000_3g_vpn_firmware
  • innominate_mguard_rs4000_4tx\/tx_vpn_firmware
  • innominate_mguard_rs4000_4tx\/tx_firmware
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn
  • fl_mguard_rs4004_tx\/dtx_vpn
  • tc_mguard_rs4000_4g_vzw_vpn
  • fl_mguard_rs4004_tx\/dtx
  • fl_mguard_rs4004_tx\/dtx_vpn_firmware
  • tc_mguard_rs4000_4g_att_vpn
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware