CVE-2022-3480

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IPs. Configuring firewall limits for incoming connections cannot prevent the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CERTVDECNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
phoenixcontactfl_mguard_centerport_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_centerport_vpn-1000_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_core_tx_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_core_tx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_delta_tx\/tx_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_delta_tx\/tx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_gt\/gt_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_gt\/gt_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_pci4000_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_pci4000_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_pcie4000_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_pcie4000_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs2000_tx\/tx-b_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs2000_tx\/tx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs2005_tx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4000_tx\/tx_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4000_tx\/tx-m_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4000_tx\/tx-p_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4000_tx\/tx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4004_tx\/dtx_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_rs4004_tx\/dtx_vpn_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_smart2_firmware
𝑥
< 8.9.0
phoenixcontactfl_mguard_smart2_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs2000_3g_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs2000_4g_att_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs2000_4g_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs2000_4g_vzw_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs4000_3g_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs4000_4g_att_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs4000_4g_vpn_firmware
𝑥
< 8.9.0
phoenixcontacttc_mguard_rs4000_4g_vzw_vpn_firmware
𝑥
< 8.9.0
𝑥
= Vulnerable software versions