Timing Attack Vulnerability in RUGGEDCOM Networking Products by Siemens
CVE-2021-42016
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 March 2022
Summary
A vulnerability exists within multiple RUGGEDCOM networking products that could allow a timing attack to compromise the private key used for encrypting sensitive data. If successfully exploited by an attacker through a third-party component, this vulnerability could lead to unauthorized access to sensitive information, thus threatening the data integrity and security of affected systems. Organizations using these products should implement the necessary fixes to ensure the security of their networks.
Affected Version(s)
RUGGEDCOM i800 All versions < V4.3.8
RUGGEDCOM i801 All versions < V4.3.8
RUGGEDCOM i802 All versions < V4.3.8
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved