CVE-2024-43385
HIGHPhoenixcontact TC Mguard Rs4000 4G Vz... - OS Command Injection
Title source: ruleDescription
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
Scores
CVSS v3
8.8
EPSS
0.0246
EPSS Percentile
85.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (36)
phoenixcontact/tc_mguard_rs4000_4g_vzw_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_att_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs4000_3g_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vzw_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_att_vpn_firmware
< 8.9.3
phoenixcontact/tc_mguard_rs2000_3g_vpn_firmware
< 8.9.3
phoenixcontact/fl_mguard_smart2_vpn_firmware
< 8.9.3
phoenixcontact/fl_mguard_smart2_firmware
< 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_vpn_firmware
< 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_firmware
< 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx_vpn_firmware
< 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-p_firmware
< 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-m_firmware
< 8.9.3
... and 21 more
Timeline
Published
Sep 10, 2024
Tracked Since
Feb 18, 2026