PT-2022-6062 · Phoenix Contact · Fl Mguard+1
Published
2022-10-13
·
Updated
2022-11-17
·
CVE-2022-3480
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PHOENIX CONTACT FL MGUARD and TC MGUARD versions prior to 8.9.0
Description
The issue is related to unlimited resource distribution in the management interface of PHOENIX CONTACT FL MGUARD and TC MGUARD devices. A remote, unauthenticated attacker could cause a denial-of-service by creating a large number of unauthenticated HTTPS connections from different source IP addresses. Configuring firewall limits for incoming connections cannot prevent the issue.
Recommendations
For versions prior to 8.9.0, update to version 8.9.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation.
Restrict incoming HTTPS connections to trusted IP addresses to reduce the risk of denial-of-service attacks.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fl Mguard
Tc Mguard