Cross-Site Request Forgery (CSRF) Vulnerability Affects RUGGEDCOM ROX Devices
CVE-2020-28398
8.8HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 10 December 2024
What is CVE-2020-28398?
A vulnerability exists in the command-line interface (CLI) feature within the web interface of several RUGGEDCOM ROX products. This vulnerability can be exploited through cross-site request forgery (CSRF), allowing attackers to manipulate device configurations. If a legitimate user is tricked into clicking a malicious link, an attacker may gain unauthorized access to modify device settings. It is essential for organizations using affected RUGGEDCOM products to update their systems to version 2.16.0 or later to mitigate potential risks.
Affected Version(s)
RUGGEDCOM ROX MX5000 0
RUGGEDCOM ROX MX5000RE 0
RUGGEDCOM ROX RX1400 0