Authorization Check Vulnerability in Siemens SCALANCE and RUGGEDCOM Products
CVE-2024-41797

5.3MEDIUM

What is CVE-2024-41797?

An incorrect authorization check has been discovered in multiple Siemens SCALANCE and RUGGEDCOM networking products, impacting versions prior to V3.1. This vulnerability allows authenticated remote attackers with 'guest' roles to execute internal commands not intended for their access level. This includes the ability to clear local system logs, potentially obfuscating malicious activities. Organizations using these products should review their security posture and consider applying necessary updates or mitigations to safeguard against unauthorized command execution.

Affected Version(s)

RUGGEDCOM RST2428P 0

SCALANCE XC316-8 0

SCALANCE XC324-4 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.