CVE-2024-43384

8.0

Phoenix Contact · FL MGUARD

A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

Executive summary

A vulnerability in multiple Phoenix Contact FL MGUARD products allows a low privileged remote attacker to acquire the root password due to improper handling of sensitive information.

Vulnerability

This is an improper removal of sensitive information before storage or transfer flaw, classified as CWE-212, which can be exploited by an authenticated attacker with low privileges via network access.

Business impact

A successful exploit grants an attacker full root level control over the affected network security devices, potentially leading to total compromise of network traffic, confidentiality breaches, and system availability disruption. With a CVSS score of 8.0, this high severity vulnerability poses significant risk to industrial control environments where secure perimeter defense is critical.

Remediation

Immediate Action: Update affected Phoenix Contact FL MGUARD devices to version 10.4.1 or later following the vendor security advisory.

Proactive Monitoring: Monitor network security logs and administrative access records for unauthorized login attempts or unexpected privilege escalation.

Compensating Controls: Restrict management interface access to trusted internal management networks and employ strict firewall rules to limit exposure.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the severe impact of root credential exposure, administrators must prioritize updating vulnerable Phoenix Contact devices. Apply the vendor security updates immediately to mitigate the risk of full system compromise.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Andrea Palanca, Nozomi Networks Security Research Team, per the CVE Program record.