MEDIUM · 5.3

CVE-2023-2673

Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the M...

Vulnerability Description

Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
PhoenixcontactFl Mguard 2102 Firmware<= 10.1.1
PhoenixcontactFl Mguard 2102-
PhoenixcontactFl Mguard 4102 Pci Firmware<= 10.1.1
PhoenixcontactFl Mguard 4102 Pci-
PhoenixcontactFl Mguard 4102 Pcie Firmware<= 10.1.1
PhoenixcontactFl Mguard 4102 Pcie-
PhoenixcontactFl Mguard 4302 Firmware<= 10.1.1
PhoenixcontactFl Mguard 4302-
PhoenixcontactFl Mguard Centerport Firmware<= 8.9.0
PhoenixcontactFl Mguard Centerport-
PhoenixcontactFl Mguard Centerport Vpn-1000 Firmware<= 8.9.0
PhoenixcontactFl Mguard Centerport Vpn-1000-
PhoenixcontactFl Mguard Core Tx Firmware<= 8.9.0
PhoenixcontactFl Mguard Core Tx-
PhoenixcontactFl Mguard Core Tx Vpn Firmware<= 8.9.0
PhoenixcontactFl Mguard Core Tx Vpn-
PhoenixcontactFl Mguard Delta Tx\/Tx Firmware<= 8.9.0
PhoenixcontactFl Mguard Delta Tx\/Tx-
PhoenixcontactFl Mguard Delta Tx\/Tx Vpn Firmware<= 8.9.0
PhoenixcontactFl Mguard Delta Tx\/Tx Vpn-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-2673?

CVE-2023-2673 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the M...

How severe is CVE-2023-2673?

CVE-2023-2673 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-2673?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Fl Mguard 2102 Firmware, Phoenixcontact Fl Mguard 2102, Phoenixcontact Fl Mguard 4102 Pci Firmware, Phoenixcontact Fl Mguard 4102 Pci, Phoenixcontact Fl Mguard 4102 Pcie Firmware.