VulnerabilityModified
CVE-2023-2673
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
MEDIUM 5.3EPSS 0.62%
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1287
- Affected
- phoenixcontact/fl mguard 2102 firmware · phoenixcontact/fl mguard 4102 pci firmware · phoenixcontact/fl mguard 4102 pcie firmware · phoenixcontact/fl mguard 4302 firmware · phoenixcontact/fl mguard centerport firmware · phoenixcontact/fl mguard centerport vpn-1000 firmware · phoenixcontact/fl mguard core tx firmware · phoenixcontact/fl mguard core tx vpn firmware · phoenixcontact/fl mguard delta tx\/tx firmware · phoenixcontact/fl mguard delta tx\/tx vpn firmware · phoenixcontact/fl mguard gt\/gt firmware · phoenixcontact/fl mguard gt\/gt vpn firmware · phoenixcontact/fl mguard pci4000 firmware · phoenixcontact/fl mguard pci4000 vpn firmware · phoenixcontact/fl mguard pcie4000 firmware · phoenixcontact/fl mguard pcie4000 vpn firmware · phoenixcontact/fl mguard rs2000 tx\/tx-b firmware · phoenixcontact/fl mguard rs2000 tx\/tx vpn firmware · phoenixcontact/fl mguard rs2005 tx vpn firmware · phoenixcontact/fl mguard rs4000 tx\/tx-m firmware · +6 more
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en/advisories/VDE-2023-010/Mitigation, Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-010/Mitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.