Timing Attack Vulnerability in RUGGEDCOM Networking Products by Siemens
CVE-2021-42016

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 March 2022

Summary

A vulnerability exists within multiple RUGGEDCOM networking products that could allow a timing attack to compromise the private key used for encrypting sensitive data. If successfully exploited by an attacker through a third-party component, this vulnerability could lead to unauthorized access to sensitive information, thus threatening the data integrity and security of affected systems. Organizations using these products should implement the necessary fixes to ensure the security of their networks.

Affected Version(s)

RUGGEDCOM i800 All versions < V4.3.8

RUGGEDCOM i801 All versions < V4.3.8

RUGGEDCOM i802 All versions < V4.3.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.