4.3
CVE-2017-7937
- EPSS 0.15%
- Veröffentlicht 19.05.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.3.0
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.3.1
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.3.2
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.4.0
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.4.1
Phoenix Contact Gmbh ≫ Mguard Firmware Version8.4.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.325 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 2.2 | 1.4 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.