Command Injection Vulnerability in RUGGEDCOM ROX MX5000 Series by Siemens
CVE-2023-36753

9.1CRITICAL

Key Information:

Summary

A command injection vulnerability has been discovered in the web interface of various RUGGEDCOM ROX devices, specifically targeting the uninstall-app App-name parameter. Due to inadequate server-side input sanitization, this flaw allows an authenticated privileged remote attacker to execute arbitrary code with root privileges, potentially compromising the entire system. Users are urged to upgrade to version V2.16.0 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

RUGGEDCOM ROX MX5000 All versions < V2.16.0

RUGGEDCOM ROX MX5000RE All versions < V2.16.0

RUGGEDCOM ROX RX1400 All versions < V2.16.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.