Vulnerability in RUGGEDCOM i800 Series and Other Devices Due to CBC Encryption Flaws
CVE-2021-42017
5.9MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 March 2022
Summary
A vulnerability in multiple RUGGEDCOM devices variants has been identified due to flaws in the CBC encryption mode used in TLS versions 1.0 to 1.2. This vulnerability allows attackers to potentially exploit communication channels, enabling man-in-the-middle attacks. Through this vulnerability, unauthorized actors can intercept and eavesdrop on encrypted communications, posing significant risks to network integrity and data confidentiality. It is crucial for users of affected RUGGEDCOM devices to update to the latest versions as recommended by Siemens to mitigate this risk.
Affected Version(s)
RUGGEDCOM i800 All versions < V4.3.8
RUGGEDCOM i801 All versions < V4.3.8
RUGGEDCOM i802 All versions < V4.3.8
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved