Cross-Site Scripting Vulnerability in RUGGEDCOM Products by Siemens
CVE-2021-37208

9.6CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 March 2022

Summary

An identified vulnerability within Siemens RUGGEDCOM products allows attackers with privileged access to execute cross-site scripting. This results from improper handling of special characters on the web server configuration page, which could lead to the exposure of sensitive information. Organizations utilizing these systems must implement mitigations to safeguard their network integrity.

Affected Version(s)

RUGGEDCOM i800 All versions < V4.3.8

RUGGEDCOM i800NC All versions < V4.3.8

RUGGEDCOM i801 All versions < V4.3.8

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.