An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95648 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-17-017-01 | us government resource third party advisory mitigation |