
CVE-2024-29980 – Unsafe Handling of IHV UEFI Variables
https://notcve.org/view.php?id=CVE-2024-29980
14 Jan 2025 — Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334. • https://www.phoenix.com/phoenix-security-notifications/cve-2024-29980 • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2024-29979 – Unsafe Handling of Phoenix UEFI Variables
https://notcve.org/view.php?id=CVE-2024-29979
14 Jan 2025 — Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334. • https://www.phoenix.com/phoenix-security-notifications/cve-2024-29979 • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2024-11497 – Phoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalation
https://notcve.org/view.php?id=CVE-2024-11497
14 Jan 2025 — An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access. • https://cert.vde.com/en/advisories/VDE-2024-070 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2024-43393 – Phoenix Contact: Configuration changes of the firewall services can lead to DoS in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43393
10 Sep 2024 — A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43392 – Phoenix Contact: Firewall reconfiguration through the FW_environment variables in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43392
10 Sep 2024 — A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS. A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.... • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43391 – Phoenix Contact: Firewall reconfiguration through the FW_PORTFORWARDING.SRC_IP in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43391
10 Sep 2024 — A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS. A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43390 – Phoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43390
10 Sep 2024 — A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43389 – Phoenix Contact: OSPF reconfiguration due to improper input validation in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43389
10 Sep 2024 — A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43388 – Phoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43388
10 Sep 2024 — A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2024-43387 – Phoenix Contact: Access files due to improper neutralization of special elements in MGUARD devices
https://notcve.org/view.php?id=CVE-2024-43387
10 Sep 2024 — A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •