First published: Tue Nov 15 2022(Updated: )
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenixcontact Mguard Centerport Firmware | <8.9.0 | |
Phoenixcontact Mguard Centerport | ||
Phoenixcontact Fl Mguard Centerport Vpn-1000 | <8.9.0 | |
Phoenixcontact Fl Mguard Centerport Vpn-1000 Firmware | ||
Phoenix Contact FL MGuard Core TX Firmware | <8.9.0 | |
Phoenix Contact FL Mguard Core Tx | ||
Phoenix Contact FL MGuard Core TX VPN Firmware | <8.9.0 | |
Phoenix Contact FL MGuard Core TX VPN Firmware | ||
Phoenix Contact FL Mguard Delta TX/TX Firmware | <8.9.0 | |
Phoenix Contact FL Mguard Delta TX/TX | ||
Phoenixcontact Fl Mguard Delta Tx/tx Vpn Firmware | <8.9.0 | |
Phoenixcontact FL Mguard Delta TX/TX VPN | ||
Phoenixcontact Fl Mguard Gt/gt Firmware | <8.9.0 | |
Phoenix Contact FL MGuard GT/GT | ||
Phoenixcontact FL Mguard GT/GT VPN Firmware | <8.9.0 | |
Phoenix Contact FL MGuard GT/GT VPN | ||
Phoenixcontact Fl Mguard Pcie4000 Firmware | <8.9.0 | |
Phoenixcontact FL MGuard PCI4000 VPN | ||
Phoenixcontact Mguard Pci4000 Vpn Firmware | <8.9.0 | |
Phoenix Contact mGuard PCI4000 VPN | ||
Phoenixcontact Fl Mguard Pcie4000 Firmware | <8.9.0 | |
Phoenix Contact FL MGuard PCIe 4000 | ||
Phoenix Contact FL Mguard PCIe4000 VPN Firmware | <8.9.0 | |
Phoenix Contact FL Mguard PCIe4000 VPN | ||
Phoenixcontact Fl Mguard Rs2000 Tx/tx-b Firmware | <8.9.0 | |
Phoenixcontact FL Mguard RS2000 Tx/Tx-b | ||
Phoenix Contact FL MGUARD RS2000 TX/TX VPN Firmware | <8.9.0 | |
Phoenix Contact FL MGuard RS2000 TX/TX VPN | ||
Phoenix Contact FL MGuard RS2005 TX VPN | <8.9.0 | |
Phoenix Contact FL MGuard RS2005 TX VPN | ||
Phoenixcontact Fl Mguard Rs4000 Tx/tx Firmware | <8.9.0 | |
Phoenix Contact FL MGuard RS4000 Tx/TX | ||
Phoenix Contact FL MGUARD RS4000 TX/TX-M Firmware | <8.9.0 | |
Phoenixcontact Fl Mguard Rs4000 Tx/tx-m | ||
Phoenixcontact Fl Mguard Rs4000 Tx/tx-p Firmware | <8.9.0 | |
Phoenix Contact FL MGUARD RS4000 TX/TX-P | ||
Phoenixcontact FL Mguard RS4000 TX/TX VPN Firmware | <8.9.0 | |
Phoenixcontact FL Mguard RS4000 Tx/TX VPN | ||
Phoenixcontact Fl Mguard Rs4004 Tx/dtx Firmware | <8.9.0 | |
Phoenix Contact FL MGuard RS4004 Tx/Dtx | ||
Phoenix Contact FL MGuard RS4004 TX/DX VPN Firmware | <8.9.0 | |
Phoenix Contact FL MGuard RS4004 Tx/Dtx VPN | ||
Phoenixcontact FL Mguard Smart2 | <8.9.0 | |
Phoenixcontact FL Mguard Smart2 | ||
Phoenix Contact FL MGUARD SMART2 VPN Firmware | <8.9.0 | |
Phoenixcontact FL Mguard Smart2 | ||
Phoenixcontact Tc Mguard Rs2000 3g Vpn | <8.9.0 | |
Phoenixcontact Tc Mguard Rs2000 3g Vpn Firmware | ||
Phoenix Contact TC MGuard RS2000 4G ATT VPN | <8.9.0 | |
Phoenix Contact TC MGuard RS2000 4G AT&T VPN Firmware | ||
Phoenix Contact TC MGuard RS2000 4G AT&T VPN Firmware | <8.9.0 | |
Phoenixcontact Mguard Rs2000 4g Vpn | ||
Phoenixcontact Tc Mguard Rs2000 4g Vpn Firmware | <8.9.0 | |
Phoenix Contact TC Mguard RS2000 4G VZW VPN | ||
Phoenix Contact mGuard RS4000 3G VPN | <8.9.0 | |
Phoenix Contact TC Mguard RS4000 3G VPN | ||
Phoenix Contact TC Mguard RS4000 4G AT&T VPN | <8.9.0 | |
Phoenix Contact TC Mguard RS4000 4G AT&T VPN | ||
Phoenix Contact mGuard RS4000 4G VPN | <8.9.0 | |
Phoenix Contact mGuard RS4000 4G VPN | ||
Phoenix Contact TC Mguard RS4000 4G VZW VPN Firmware | <8.9.0 | |
Phoenix Contact TC Mguard RS4000 4G VZW VPN Firmware |
Upgrade to firmware version >= 8.9.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3480 has a critical severity rating as it allows an unauthenticated remote denial-of-service attack.
To fix CVE-2022-3480, upgrade the affected Phoenix Contact FL MGuard and TC MGuard devices to a version greater than 8.9.0.
CVE-2022-3480 affects various models of Phoenix Contact FL and TC MGuard devices running firmware versions below 8.9.0.
CVE-2022-3480 describes a remote denial-of-service attack that exploits a large number of unauthenticated HTTPS connections.
Yes, CVE-2022-3480 is patched in firmware version 8.9.0 and later for affected devices.