CVE-2024-7734: Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7734?
The severity of CVE-2024-7734 is moderate, as it allows an unauthenticated remote attacker to disrupt valid IPsec VPN connections.
How do I fix CVE-2024-7734?
To fix CVE-2024-7734, update the affected Phoenixcontact firmware to version 8.9.3 or higher.
Who is affected by CVE-2024-7734?
CVE-2024-7734 affects multiple Phoenixcontact TC Mguard and FL Mguard VPN firmware versions below 8.9.3.
What type of attack does CVE-2024-7734 facilitate?
CVE-2024-7734 facilitates denial-of-service attacks by allowing attackers to overwhelm the pathfinder TCP encapsulation service.
What impact does CVE-2024-7734 have on network services?
CVE-2024-7734 can lead to the blocking of valid IPsec VPN peers, potentially disrupting secure communications.