CVE-2018-5441
Last modified
CVE-2018-5441 is a vulnerability of currently unknown severity. An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Mguard Centerport Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Delta Tx\/Tx Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Delta Tx\/Tx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Gt\/Gt Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Gt\/Gt Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Pci4000 Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Pcie4000 Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs2000 Tx\/Tx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs2000 Tx\/Tx-B Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs2005 Tx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 Tx\/Tx Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 Tx\/Tx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 Tx\/Tx Vpn-M Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 Tx\/Tx-P Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4004 Tx\/Dtx Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4004 Tx\/Dtx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Smart2 Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Smart2 Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs2000 3g Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 3g Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Core Tx Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs2000 4g Vpn Firmware | >= 7.2.0, <= 8.6.0 |
| Phoenixcontact | Mguard Rs4000 4g Vpn Firmware | >= 7.2.0, <= 8.6.0 |
References
- http://www.securityfocus.com/bid/102907Third Party Advisory, VDB Entry
- https://cert.vde.com/en-us/advisories/vde-2018-001Patch, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-030-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102907Third Party Advisory, VDB Entry
- https://cert.vde.com/en-us/advisories/vde-2018-001Patch, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-030-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5441?
How severe is CVE-2018-5441?
How do I fix CVE-2018-5441?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5435The TIBCO Spotfire Client and TIBCO Spotfire Web Player Clie…9.6
- CVE-2018-5436The Spotfire server component of TIBCO Software Inc.'s TIBCO…6.5
- CVE-2018-5437The TIBCO Spotfire Client and TIBCO Spotfire Web Player Clie…6.8
- CVE-2018-5438Philips ISCV application prior to version 2.3.0 has an insuf…
- CVE-2018-5439A Command Injection issue was discovered in Nortek Linear eM…
- CVE-2018-5440A Stack-based Buffer Overflow issue was discovered in 3S-Sma…9.8
- CVE-2018-5442A Stack-based Buffer Overflow issue was discovered in Fuji E…9.8
- CVE-2018-5443A SQL Injection issue was discovered in Advantech WebAccess/…
- CVE-2018-5445A Path Traversal issue was discovered in Advantech WebAccess…
- CVE-2018-5446Medtronic 2090 CareLink Programmer uses a per-product user…4.9
- CVE-2018-5447An Improper Input Validation issue was discovered in Nari PC…
- CVE-2018-5448Medtronic 2090 CareLink Programmer’s software deployment net…4.8
Are you affected by CVE-2018-5441?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
