Malformed HTTP Packet Handling Vulnerability in RUGGEDCOM ROX Products
CVE-2022-29562
3.7LOW
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 July 2023
Summary
A vulnerability in various RUGGEDCOM ROX products has been identified, where devices fail to process malformed HTTP packets correctly. This flaw could allow an unauthenticated remote attacker to send specially crafted HTTP packets, potentially causing specific functions to fail in a controlled manner. Systems operating on versions prior to V2.16.0 are particularly at risk, necessitating immediate attention to ensure proper security measures are in place.
Affected Version(s)
RUGGEDCOM ROX MX5000 All versions < V2.16.0
RUGGEDCOM ROX MX5000RE All versions < V2.16.0
RUGGEDCOM ROX RX1400 All versions < V2.16.0
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved