PT-2021-7544 · Phoenix Contact+2 · Fl Mguard Dm+2
Published
2021-08-11
·
Updated
2022-11-15
·
CVE-2021-34579
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Phoenix Contact: FL MGUARD DM versions 1.12.0 through 1.13.0
Description
The issue is related to inadequate access control in the Apache web server installed as part of the FL MGUARD DM on Microsoft Windows. Attackers with network access to the Apache web server can download and read mGuard configuration profiles, also known as "ATV profiles", which may contain sensitive information such as private keys associated with IPsec VPN connections.
Recommendations
For versions 1.12.0 and 1.13.0, consider restricting access to the Apache web server to minimize the risk of exploitation. As a temporary workaround, limit the ability to download configuration profiles until a patch is available. Additionally, review and secure any sensitive information stored in the configuration profiles. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Web Server
Fl Mguard Dm
Windows