Remote Code Execution Risk in RUGGEDCOM ROS by Siemens
CVE-2021-31895

8.1HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
13 July 2021

What is CVE-2021-31895?

A significant vulnerability has been found in multiple versions of Siemens RUGGEDCOM ROS. Specifically, the DHCP client within these devices inadequately sanitizes incoming DHCP packets. This weakness allows malicious actors to craft malicious DHCP packets that, when processed by the affected devices, can lead to memory corruption. The exploit could potentially enable unauthorized remote code execution, compromising the security and integrity of the affected network devices.

Affected Version(s)

RUGGEDCOM i800 All versions < V4.3.7

RUGGEDCOM i801 All versions < V4.3.7

RUGGEDCOM i802 All versions < V4.3.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.