Command Injection Vulnerability in RUGGEDCOM ROX Products by Siemens
CVE-2023-36751

9.1CRITICAL

Key Information:

Summary

A command injection vulnerability has been discovered in the web interface of RUGGEDCOM ROX devices, stemming from inadequate server-side input sanitization of the install-app URL parameter. This flaw allows an authenticated attacker with privileged access to execute arbitrary commands, potentially gaining root access. Affected devices include RUGGEDCOM ROX MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, and RX5000, all prior to version 2.16.0. It is essential for users to upgrade their systems to the latest version to mitigate the risk of exploitation.

Affected Version(s)

RUGGEDCOM ROX MX5000 All versions < V2.16.0

RUGGEDCOM ROX MX5000RE All versions < V2.16.0

RUGGEDCOM ROX RX1400 All versions < V2.16.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.