CVE Vulnerabilities

CVE-2017-7937

Improper Authentication

Published: May 19, 2017 | Modified: Apr 20, 2025
CVSS 3.x
4
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Mguard_firmwarePhoenix_contact_gmbh8.3.0 (including)8.3.0 (including)
Mguard_firmwarePhoenix_contact_gmbh8.3.1 (including)8.3.1 (including)
Mguard_firmwarePhoenix_contact_gmbh8.3.2 (including)8.3.2 (including)
Mguard_firmwarePhoenix_contact_gmbh8.4.0 (including)8.4.0 (including)
Mguard_firmwarePhoenix_contact_gmbh8.4.1 (including)8.4.1 (including)
Mguard_firmwarePhoenix_contact_gmbh8.4.2 (including)8.4.2 (including)

Potential Mitigations

References