Back to Database
Status published
Medium
CVE-2021-34582
Phoenix Contact: FL MGUARD XSS through web-based management and REST API
Vulnerability Description
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34582
Credits & Attribution
No credits recorded in the NVD database.
More from PHOENIX CONTACT
View All →CVE-2025-41668
Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile
High
8.8
CVE-2025-41667
Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script
High
8.8
CVE-2025-41666
Phoenix Contact: File access due to the replacement of a critical file used by the watchdog
High
8.8
CVE-2025-41665
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible
Medium
6.5
CVE-2024-7734
Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
Medium
5.3
Affected Vendor
PHOENIX CONTACT
View all reports →Affected Software
FL MGUARD
Vulnerable Versions:
1.4.0
Timeline
Official Publish:
November 10th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N