Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Phoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devices
Vulnerability Description
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
PHOENIX CONTACT FL/TC MGUARD 注入漏洞
Vulnerability Description
PHOENIX CONTACT FL/TC MGUARD是德国菲尼克斯电气(PHOENIX)公司的一系列路由器。 PHOENIX CONTACT FL/TC MGUARD存在注入漏洞。低权限远程攻击者可以对防火墙服务进行配置更改,包括通过 FW_NAT.IN_IP 环境变量进行数据包转发或 NAT,这可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A