Vulnerabilities > Phoenixcontact > FL Mguard Pcie4000 VPN Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-43385 OS Command Injection vulnerability in Phoenixcontact products
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
network
low complexity
phoenixcontact CWE-78
8.8
2024-09-10 CVE-2024-43386 OS Command Injection vulnerability in Phoenixcontact products
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
network
low complexity
phoenixcontact CWE-78
8.8
2024-09-10 CVE-2024-43387 OS Command Injection vulnerability in Phoenixcontact products
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
network
low complexity
phoenixcontact CWE-78
8.8
2024-09-10 CVE-2024-43388 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
network
low complexity
phoenixcontact
8.8
2024-09-10 CVE-2024-43389 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
network
low complexity
phoenixcontact
8.1
2024-09-10 CVE-2024-43390 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
network
low complexity
phoenixcontact
8.1
2024-09-10 CVE-2024-43391 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.
network
low complexity
phoenixcontact
8.1
2024-09-10 CVE-2024-43392 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.
network
low complexity
phoenixcontact
8.1
2024-09-10 CVE-2024-43393 Unspecified vulnerability in Phoenixcontact products
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.
network
low complexity
phoenixcontact
8.1
2024-09-10 CVE-2024-7699 OS Command Injection vulnerability in Phoenixcontact products
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
network
low complexity
phoenixcontact CWE-78
8.8