CVE-2024-43386
HIGHDescription
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
Is your site exposed to CVE-2024-43386?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| phoenixcontact | tc_mguard_rs4000_4g_vzw_vpn_firmware |
| phoenixcontact | tc_mguard_rs4000_4g_vzw_vpn |
| phoenixcontact | tc_mguard_rs4000_4g_vpn_firmware |
| phoenixcontact | tc_mguard_rs4000_4g_vpn |
| phoenixcontact | tc_mguard_rs4000_4g_att_vpn_firmware |
| phoenixcontact | tc_mguard_rs4000_4g_att_vpn |
| phoenixcontact | tc_mguard_rs4000_3g_vpn_firmware |
| phoenixcontact | tc_mguard_rs4000_3g_vpn |
| phoenixcontact | tc_mguard_rs2000_4g_vzw_vpn_firmware |
| phoenixcontact | tc_mguard_rs2000_4g_vzw_vpn |
| phoenixcontact | tc_mguard_rs2000_4g_vpn_firmware |
| phoenixcontact | tc_mguard_rs2000_4g_vpn |
| phoenixcontact | tc_mguard_rs2000_4g_att_vpn_firmware |
| phoenixcontact | tc_mguard_rs2000_4g_att_vpn |
| phoenixcontact | tc_mguard_rs2000_3g_vpn_firmware |
| phoenixcontact | tc_mguard_rs2000_3g_vpn |
| phoenixcontact | fl_mguard_smart2_vpn_firmware |
| phoenixcontact | fl_mguard_smart2_vpn |
| phoenixcontact | fl_mguard_smart2_firmware |
| phoenixcontact | fl_mguard_smart2 |
| phoenixcontact | fl_mguard_rs4004_tx\/dtx_vpn_firmware |
| phoenixcontact | fl_mguard_rs4004_tx\/dtx_vpn |
| phoenixcontact | fl_mguard_rs4004_tx\/dtx_firmware |
| phoenixcontact | fl_mguard_rs4004_tx\/dtx |
| phoenixcontact | fl_mguard_rs4000_tx\/tx_vpn_firmware |
| phoenixcontact | fl_mguard_rs4000_tx\/tx_vpn |
| phoenixcontact | fl_mguard_rs4000_tx\/tx-p_firmware |
| phoenixcontact | fl_mguard_rs4000_tx\/tx-p |
| phoenixcontact | fl_mguard_rs4000_tx\/tx-m_firmware |
| phoenixcontact | fl_mguard_rs4000_tx\/tx-m |
| phoenixcontact | fl_mguard_rs4000_tx\/tx_firmware |
| phoenixcontact | fl_mguard_rs4000_tx\/tx |
| phoenixcontact | fl_mguard_rs2005_tx_vpn_firmware |
| phoenixcontact | fl_mguard_rs2005_tx_vpn |
| phoenixcontact | fl_mguard_rs2000_tx\/tx_vpn_firmware |
| phoenixcontact | fl_mguard_rs2000_tx\/tx_vpn |
| phoenixcontact | fl_mguard_rs2000_tx\/tx-b_firmware |
| phoenixcontact | fl_mguard_rs2000_tx\/tx-b |
| phoenixcontact | fl_mguard_pcie4000_vpn_firmware |
| phoenixcontact | fl_mguard_pcie4000_vpn |
| phoenixcontact | fl_mguard_pcie4000_firmware |
| phoenixcontact | fl_mguard_pcie4000 |
| phoenixcontact | fl_mguard_pci4000_vpn_firmware |
| phoenixcontact | fl_mguard_pci4000_vpn |
| phoenixcontact | fl_mguard_pci4000_firmware |
| phoenixcontact | fl_mguard_pci4000 |
| phoenixcontact | fl_mguard_gt\/gt_vpn_firmware |
| phoenixcontact | fl_mguard_gt\/gt_vpn |
| phoenixcontact | fl_mguard_gt\/gt_firmware |
| phoenixcontact | fl_mguard_gt\/gt |
| phoenixcontact | fl_mguard_delta_tx\/tx_vpn_firmware |
| phoenixcontact | fl_mguard_delta_tx\/tx_vpn |
| phoenixcontact | fl_mguard_delta_tx\/tx_firmware |
| phoenixcontact | fl_mguard_delta_tx\/tx |
| phoenixcontact | fl_mguard_core_tx_vpn_firmware |
| phoenixcontact | fl_mguard_core_tx_vpn |
| phoenixcontact | fl_mguard_core_tx_firmware |
| phoenixcontact | fl_mguard_core_tx |
| phoenixcontact | fl_mguard_centerport_vpn-1000_firmware |
| phoenixcontact | fl_mguard_centerport_vpn-1000 |
| phoenixcontact | fl_mguard_4305_firmware |
| phoenixcontact | fl_mguard_4305 |
| phoenixcontact | fl_mguard_4302_firmware |
| phoenixcontact | fl_mguard_4302 |
| phoenixcontact | fl_mguard_4102_pcie_firmware |
| phoenixcontact | fl_mguard_4102_pcie |
| phoenixcontact | fl_mguard_4102_pci_firmware |
| phoenixcontact | fl_mguard_4102_pci |
| phoenixcontact | fl_mguard_2105_firmware |
| phoenixcontact | fl_mguard_2105 |
| phoenixcontact | fl_mguard_2102_firmware |
| phoenixcontact | fl_mguard_2102 |
References
Other References
Frequently Asked Questions
What is CVE-2024-43386? +
How severe is CVE-2024-43386? +
What products are affected by CVE-2024-43386? +
How do I check if I'm vulnerable to CVE-2024-43386? +
Related Vulnerabilities
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted …
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web …
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated …