CVE-2020-12523: Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configuration
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12523?
CVE-2020-12523 is a vulnerability found in Phoenix Contact mGuard Devices versions before 8.8.3 that allows LAN ports to become functional after a reboot, even if they were disabled in the device configuration.
How severe is CVE-2020-12523?
CVE-2020-12523 has a severity rating of 9.1 (Critical).
How can I fix CVE-2020-12523?
To fix CVE-2020-12523, it is recommended to update the mGuard Devices to version 8.8.3 or higher.
Where can I find more information about CVE-2020-12523?
You can find more information about CVE-2020-12523 on the CERT VDE advisory page: https://cert.vde.com/en-us/advisories/vde-2020-046
What is the Common Weakness Enumeration (CWE) for CVE-2020-12523?
The Common Weakness Enumeration (CWE) for CVE-2020-12523 is CWE-909.