Executive brief
Phoenix Contact mGuard security appliances, which are used to protect industrial networks, contain a vulnerability that could allow an attacker to obtain the root password. A remote attacker with low-level access could exploit this flaw to gain full administrative control over the device. This could lead to unauthorized network access, data theft, or disruption of industrial operations.
Technical details
The vulnerability is classified as CWE-212 (Improper Removal of Sensitive Information Before Storage or Transfer). It exists within the administrative web interface of various Phoenix Contact mGuard security appliances. A remote attacker with low-privileged credentials can exploit this flaw, though it requires some level of user interaction (UI:R). Successful exploitation allows the attacker to retrieve the root password, leading to full system compromise and privilege escalation. The issue is addressed in firmware versions 10.4.1 and 8.9.3 depending on the specific hardware model.
Affected products
- Phoenix Contact FL MGUARD 2102 Firmware < 10.4.1
- Phoenix Contact FL MGUARD 2105 Firmware < 10.4.1
- Phoenix Contact FL MGUARD 4102 PCI Firmware < 10.4.1
- Phoenix Contact FL MGUARD 4102 PCIE Firmware < 10.4.1
- Phoenix Contact FL MGUARD 4302 Firmware < 10.4.1
- Phoenix Contact FL MGUARD 4305 Firmware < 10.4.1
- Phoenix Contact FL MGUARD CENTERPORT Firmware < 8.9.3
- Phoenix Contact FL MGUARD CORE TX Firmware < 8.9.3
- Phoenix Contact FL MGUARD RS2000 TX/TX VPN Firmware < 8.9.3
- Phoenix Contact TC MGUARD RS4000 4G VPN Firmware < 8.9.3
Timeline
- 2024-09-10: advisory: Initial advisory published by CERT@VDE
- 2026-05-07: disclosed: CVE published to NVD