Куда я попал?
CVE-2024-7698
PUBLISHED
10.09.2024
CNA: CERTVDE
Phoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD products
Обновлено:
10.09.2024
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
CWE
Идентификатор | Описание |
---|---|
CWE-212 | CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer |
CVSS
Оценка | Severity | Версия | Базовый вектор |
---|---|---|---|
5.7 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Доп. Информация
Product Status
FL MGUARD 2102 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 2102 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD 2105 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 2105 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD 4102 PCI | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 4102 PCI | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD 4102 PCIE | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 4102 PCIE | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD 4302 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 4302 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD 4305 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD 4305 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD CENTERPORT VPN-1000 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD CENTERPORT VPN-1000 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD CORE TX | |||||
---|---|---|---|---|---|
Product: | FL MGUARD CORE TX | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD CORE TX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD CORE TX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD DELTA TX/TX | |||||
---|---|---|---|---|---|
Product: | FL MGUARD DELTA TX/TX | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD DELTA TX/TX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD DELTA TX/TX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD GT/GT | |||||
---|---|---|---|---|---|
Product: | FL MGUARD GT/GT | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD GT/GT VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD GT/GT VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD PCI4000 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD PCI4000 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD PCI4000 VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD PCI4000 VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD PCIE4000 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD PCIE4000 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD PCIE4000 VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD PCIE4000 VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS2000 TX/TX-B | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS2000 TX/TX-B | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS2000 TX/TX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS2000 TX/TX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS2005 TX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS2005 TX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4000 TX/TX | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4000 TX/TX | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4000 TX/TX-M | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4000 TX/TX-M | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4000 TX/TX-P | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4000 TX/TX-P | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4000 TX/TX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4000 TX/TX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4004 TX/DTX | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4004 TX/DTX | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD RS4004 TX/DTX VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD RS4004 TX/DTX VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD SMART2 | |||||
---|---|---|---|---|---|
Product: | FL MGUARD SMART2 | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
FL MGUARD SMART2 VPN | |||||
---|---|---|---|---|---|
Product: | FL MGUARD SMART2 VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS2000 3G VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS2000 3G VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS2000 4G ATT VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS2000 4G ATT VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS2000 4G VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS2000 4G VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS2000 4G VZW VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS2000 4G VZW VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS4000 3G VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS4000 3G VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS4000 4G ATT VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS4000 4G ATT VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS4000 4G VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS4000 4G VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
TC MGUARD RS4000 4G VZW VPN | |||||
---|---|---|---|---|---|
Product: | TC MGUARD RS4000 4G VZW VPN | ||||
Vendor: | PHOENIX CONTACT | ||||
Default status: | unaffected | ||||
Версии: |
|
Ссылки
CISA ADP Vulnrichment
Обновлено:
10.09.2024
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.
SSVC
Exploitation | Automatable | Technical Impact | Версия | Дата доступа |
---|---|---|---|---|
none | no | partial | 2.0.3 | 10.09.2024 |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.