CVE-2024-43392

HIGH

Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection

Title source: rule

Description

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.

Scores

CVSS v3 8.1
EPSS 0.0050
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-94
Status published

Affected Products (30)

phoenixcontact/tc_mguard_rs4000_4g_vzw_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_att_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_3g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vzw_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_att_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_3g_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_smart2_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_smart2_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-p_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-m_firmware < 8.9.3
... and 15 more

Timeline

Published Sep 10, 2024
Tracked Since Feb 18, 2026