Arbitrary Code Execution Vulnerability in Siemens Networking Products
CVE-2022-34821

8.8HIGH

Key Information:

Summary

A vulnerability exists in certain Siemens devices that allows an attacker to execute arbitrary code with elevated privileges by injecting malicious commands into specific OpenVPN configuration options. This can lead to significant security risks, potentially allowing unauthorized access to sensitive systems and data.

Affected Version(s)

RUGGEDCOM RM1224 LTE(4G) EU 0

RUGGEDCOM RM1224 LTE(4G) NAM 0

SCALANCE M804PB 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.