Command Injection Vulnerability in RUGGEDCOM ROX Devices by Siemens
CVE-2023-36752

9.1CRITICAL

Key Information:

Summary

A command injection vulnerability exists in various RUGGEDCOM ROX devices due to inadequate server-side input validation on the upgrade-app URL parameter in the web interface. This flaw permits an authenticated privileged remote attacker to execute arbitrary commands with root privileges, potentially exposing sensitive system data and compromising device integrity. Users are urged to upgrade to version V2.16.0 or later to mitigate this risk. For detailed information, please refer to the advisory issued by Siemens.

Affected Version(s)

RUGGEDCOM ROX MX5000 All versions < V2.16.0

RUGGEDCOM ROX MX5000RE All versions < V2.16.0

RUGGEDCOM ROX RX1400 All versions < V2.16.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.