CVE-2023-2673
Last modified
CVE-2023-2673 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Fl Mguard 2102 Firmware | <= 10.1.1 |
| Phoenixcontact | Fl Mguard 4102 Pci Firmware | <= 10.1.1 |
| Phoenixcontact | Fl Mguard 4102 Pcie Firmware | <= 10.1.1 |
| Phoenixcontact | Fl Mguard 4302 Firmware | <= 10.1.1 |
| Phoenixcontact | Fl Mguard Centerport Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Centerport Vpn-1000 Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Core Tx Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Core Tx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Delta Tx\/Tx Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Delta Tx\/Tx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Gt\/Gt Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Gt\/Gt Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Pci4000 Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Pci4000 Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Pcie4000 Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Pcie4000 Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs2000 Tx\/Tx-B Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs2000 Tx\/Tx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs2005 Tx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs4000 Tx\/Tx-M Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs4000 Tx\/Tx-P Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs4000 Tx\/Tx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs4004 Tx\/Dtx Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Rs4004 Tx\/Dtx Vpn Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Smart2 Firmware | <= 8.9.0 |
| Phoenixcontact | Fl Mguard Smart2 Vpn Firmware | <= 8.9.0 |
References
- https://cert.vde.com/en/advisories/VDE-2023-010/Mitigation, Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-010/Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-2673?
How severe is CVE-2023-2673?
How do I fix CVE-2023-2673?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-26690File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allo…8.8
- CVE-2023-26691Directory Traversal vulnerability in CS-Cart MultiVendor 4.1…7.2
- CVE-2023-26692ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publicat…6.1
- CVE-2023-2670A vulnerability was found in SourceCodester Lost and Found I…8.8
- CVE-2023-2671A vulnerability was found in SourceCodester Lost and Found I…6.1
- CVE-2023-2672A vulnerability classified as critical has been found in Sou…9.8
- CVE-2023-26733Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows…7.8
- CVE-2023-26735blackbox_exporter v0.23.0 was discovered to contain an acces…7.5
- CVE-2023-2674Improper Access Control in GitHub repository openemr/openemr…4.3
- CVE-2023-2675Improper Restriction of Excessive Authentication Attempts in…9.8
- CVE-2023-26750SQL injection vulnerability found in Yii Framework Yii 2 Fra…9.8
- CVE-2023-26756The login page of Revive Adserver v5.4.1 is vulnerable to br…7.5
Are you affected by CVE-2023-2673?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
