Description
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
Published: 2020-12-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

PHOENIX CONTACT recommends all mGuard users to upgrade to the firmware version 8.8.3.


Vendor Workaround

Instead of deactivating by configuration, network cables should be detached from affected switch ports.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4825 On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
History

No history.

Subscriptions

Phoenixcontact Fl Mguard Rs4004 Tx\/dtx Fl Mguard Rs4004 Tx\/dtx Firmware Fl Mguard Rs4004 Tx\/dtx Vpn Fl Mguard Rs4004 Tx\/dtx Vpn Firmware Innominate Mguard Rs4000 4tx\/3g\/tx Vpn Innominate Mguard Rs4000 4tx\/3g\/tx Vpn Firmware Innominate Mguard Rs4000 4tx\/tx Innominate Mguard Rs4000 4tx\/tx Firmware Innominate Mguard Rs4000 4tx\/tx Vpn Innominate Mguard Rs4000 4tx\/tx Vpn Firmware Tc Mguard Rs4000 3g Vpn Tc Mguard Rs4000 3g Vpn Firmware Tc Mguard Rs4000 4g Att Vpn Tc Mguard Rs4000 4g Att Vpn Firmware Tc Mguard Rs4000 4g Vpn Tc Mguard Rs4000 4g Vpn Firmware Tc Mguard Rs4000 4g Vzw Vpn Tc Mguard Rs4000 4g Vzw Vpn Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T19:04:46.625Z

Reserved: 2020-04-30T00:00:00.000Z

Link: CVE-2020-12523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-17T23:15:13.263

Modified: 2024-11-21T04:59:51.767

Link: CVE-2020-12523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses