7.8
CVSSv3

CVE-2018-5441

Published: 30/01/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An Improper Validation of Integrity Check Value issue exists in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an malicious user to modify firmware update packages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact mguard_centerport_firmware

phoenixcontact mguard_delta_tx\\/tx_firmware

phoenixcontact mguard_delta_tx\\/tx_vpn_firmware

phoenixcontact mguard_gt\\/gt_firmware

phoenixcontact mguard_gt\\/gt_vpn_firmware

phoenixcontact mguard_pci4000_vpn_firmware

phoenixcontact mguard_pcie4000_vpn_firmware

phoenixcontact mguard_rs2000_tx\\/tx_vpn_firmware

phoenixcontact mguard_rs2000_tx\\/tx-b_firmware

phoenixcontact mguard_rs2005_tx_vpn_firmware

phoenixcontact mguard_rs4000_tx\\/tx_firmware

phoenixcontact mguard_rs4000_tx\\/tx_vpn_firmware

phoenixcontact mguard_rs4000_tx\\/tx_vpn-m_firmware

phoenixcontact mguard_rs4000_tx\\/tx-p_firmware

phoenixcontact mguard_rs4004_tx\\/dtx_firmware

phoenixcontact mguard_rs4004_tx\\/dtx_vpn_firmware

phoenixcontact mguard_smart2_firmware

phoenixcontact mguard_smart2_vpn_firmware

phoenixcontact mguard_rs2000_3g_vpn_firmware

phoenixcontact mguard_rs4000_3g_vpn_firmware

phoenixcontact mguard_core_tx_vpn_firmware

phoenixcontact mguard_rs2000_4g_vpn_firmware

phoenixcontact mguard_rs4000_4g_vpn_firmware