ZeroHour

CVE-2022-3480

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.

Vendors
phoenixcontact
Products
fl mguard centerport firmware, fl mguard centerport vpn-1000 firmware, fl mguard core tx firmware, fl mguard core tx vpn firmware, fl mguard delta tx\/tx firmware, fl mguard delta tx\/tx vpn firmware, fl mguard gt\/gt firmware, fl mguard gt\/gt vpn firmware, fl mguard pci4000 firmware, fl mguard pci4000 vpn firmware, fl mguard pcie4000 firmware, fl mguard pcie4000 vpn firmware
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.