{ "id": "CVE-2021-34598", "sourceIdentifier": "info@cert.vde.com", "published": "2021-11-10T12:15:16.160", "lastModified": "2022-07-28T09:34:04.833", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active" }, { "lang": "es", "value": "En Phoenix Contact FL MGUARD 1102 y 1105 en las versiones 1.4.0, 1.4.1 y 1.5.0, la funcionalidad remote logging est\u00e1 afectada por una falta de liberaci\u00f3n de memoria para las estructuras de datos de syslog-ng cuando el registro remoto est\u00e1 activo" } ], "metrics": { "cvssMetricV31": [ { "source": "info@cert.vde.com", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "info@cert.vde.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-401" } ] }, { "source": "nvd@nist.gov", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-401" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1102_firmware:1.4.0:*:*:*:*:*:*:*", "matchCriteriaId": "AA1C71EF-C44F-4661-83AA-B65B704AE0B4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1102_firmware:1.4.1:*:*:*:*:*:*:*", "matchCriteriaId": "1819CD97-D92F-42A0-B8DB-C13D0B8D93B2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1102_firmware:1.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "EF940FF8-56F3-40CB-B978-78C1F0985E87" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:phoenixcontact:fl_mguard_1102:-:*:*:*:*:*:*:*", "matchCriteriaId": "093DE0FB-96BE-4971-A6A5-6404F02CB6CB" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1105_firmware:1.4.0:*:*:*:*:*:*:*", "matchCriteriaId": "97534DA1-F536-454B-8ABD-B251A7B4AB9D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1105_firmware:1.4.1:*:*:*:*:*:*:*", "matchCriteriaId": "FE12A61D-73FD-423D-B7E5-C43EE7E4FC71" }, { "vulnerable": true, "criteria": "cpe:2.3:o:phoenixcontact:fl_mguard_1105_firmware:1.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "BD02E727-CC42-4965-BC35-23CF0B63338F" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:phoenixcontact:fl_mguard_1105:-:*:*:*:*:*:*:*", "matchCriteriaId": "E72161DC-0AC0-4603-A0CB-73940B951D66" } ] } ] } ], "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2021-046/", "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ] } ] }