On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
Project Subscriptions
| Vendors | Products |
|---|---|
|
Phoenixcontact
Subscribe
|
Fl Mguard Rs4004 Tx\/dtx
Subscribe
Fl Mguard Rs4004 Tx\/dtx Firmware
Subscribe
Fl Mguard Rs4004 Tx\/dtx Vpn
Subscribe
Fl Mguard Rs4004 Tx\/dtx Vpn Firmware
Subscribe
Innominate Mguard Rs4000 4tx\/3g\/tx Vpn
Subscribe
Innominate Mguard Rs4000 4tx\/3g\/tx Vpn Firmware
Subscribe
Innominate Mguard Rs4000 4tx\/tx
Subscribe
Innominate Mguard Rs4000 4tx\/tx Firmware
Subscribe
Innominate Mguard Rs4000 4tx\/tx Vpn
Subscribe
Innominate Mguard Rs4000 4tx\/tx Vpn Firmware
Subscribe
Tc Mguard Rs4000 3g Vpn
Subscribe
Tc Mguard Rs4000 3g Vpn Firmware
Subscribe
Tc Mguard Rs4000 4g Att Vpn
Subscribe
Tc Mguard Rs4000 4g Att Vpn Firmware
Subscribe
Tc Mguard Rs4000 4g Vpn
Subscribe
Tc Mguard Rs4000 4g Vpn Firmware
Subscribe
Tc Mguard Rs4000 4g Vzw Vpn
Subscribe
Tc Mguard Rs4000 4g Vzw Vpn Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4825 | On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource |
Fixes
Solution
PHOENIX CONTACT recommends all mGuard users to upgrade to the firmware version 8.8.3.
Workaround
Instead of deactivating by configuration, network cables should be detached from affected switch ports.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2020-046 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-16T19:04:46.625Z
Reserved: 2020-04-30T00:00:00
Link: CVE-2020-12523
No data.
Status : Modified
Published: 2020-12-17T23:15:13.263
Modified: 2024-11-21T04:59:51.767
Link: CVE-2020-12523
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD