CVE-2020-12523

On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2020-046 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vzw_vpn:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_att_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_att_vpn:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fl_mguard_rs4004_tx\/dtx_vpn:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_3g_vpn_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_3g_vpn:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:tc_mguard_rs4000_4g_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:tc_mguard_rs4000_4g_vpn:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/tx_vpn:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:innominate_mguard_rs4000_4tx\/3g\/tx_vpn:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-12-17 23:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-12523

Mitre link : CVE-2020-12523

CVE.ORG link : CVE-2020-12523


JSON object : View

Products Affected

phoenixcontact

  • innominate_mguard_rs4000_4tx\/tx_vpn_firmware
  • fl_mguard_rs4004_tx\/dtx_vpn_firmware
  • tc_mguard_rs4000_4g_vzw_vpn
  • tc_mguard_rs4000_4g_vpn_firmware
  • tc_mguard_rs4000_3g_vpn
  • fl_mguard_rs4004_tx\/dtx_firmware
  • tc_mguard_rs4000_3g_vpn_firmware
  • tc_mguard_rs4000_4g_vpn
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn_firmware
  • innominate_mguard_rs4000_4tx\/3g\/tx_vpn
  • tc_mguard_rs4000_4g_vzw_vpn_firmware
  • tc_mguard_rs4000_4g_att_vpn_firmware
  • fl_mguard_rs4004_tx\/dtx_vpn
  • tc_mguard_rs4000_4g_att_vpn
  • fl_mguard_rs4004_tx\/dtx
  • innominate_mguard_rs4000_4tx\/tx
  • innominate_mguard_rs4000_4tx\/tx_vpn
  • innominate_mguard_rs4000_4tx\/tx_firmware
CWE
CWE-909

Missing Initialization of Resource