CVE-2018-5441
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354, CWE-20
- Affected
- phoenixcontact/mguard centerport firmware · phoenixcontact/mguard delta tx\/tx firmware · phoenixcontact/mguard delta tx\/tx vpn firmware · phoenixcontact/mguard gt\/gt firmware · phoenixcontact/mguard gt\/gt vpn firmware · phoenixcontact/mguard pci4000 vpn firmware · phoenixcontact/mguard pcie4000 vpn firmware · phoenixcontact/mguard rs2000 tx\/tx vpn firmware · phoenixcontact/mguard rs2000 tx\/tx-b firmware · phoenixcontact/mguard rs2005 tx vpn firmware · phoenixcontact/mguard rs4000 tx\/tx firmware · phoenixcontact/mguard rs4000 tx\/tx vpn firmware · phoenixcontact/mguard rs4000 tx\/tx vpn-m firmware · phoenixcontact/mguard rs4000 tx\/tx-p firmware · phoenixcontact/mguard rs4004 tx\/dtx firmware · phoenixcontact/mguard rs4004 tx\/dtx vpn firmware · phoenixcontact/mguard smart2 firmware · phoenixcontact/mguard smart2 vpn firmware · phoenixcontact/mguard rs2000 3g vpn firmware · phoenixcontact/mguard rs4000 3g vpn firmware · +3 more
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/102907Third Party Advisory, VDB Entry
- https://cert.vde.com/en-us/advisories/vde-2018-001Patch, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-030-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102907Third Party Advisory, VDB Entry
- https://cert.vde.com/en-us/advisories/vde-2018-001Patch, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-030-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.