PT-2023-4075 · Siemens · Ruggedcom Rox Rx1500+8
CVE-2023-36750
·
Publicado
2023-06-27
·
Atualizado
2023-07-18
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM ROX MX5000 versions prior to V2.16.0
RUGGEDCOM ROX MX5000RE versions prior to V2.16.0
RUGGEDCOM ROX RX1400 versions prior to V2.16.0
RUGGEDCOM ROX RX1500 versions prior to V2.16.0
RUGGEDCOM ROX RX1501 versions prior to V2.16.0
RUGGEDCOM ROX RX1510 versions prior to V2.16.0
RUGGEDCOM ROX RX1511 versions prior to V2.16.0
RUGGEDCOM ROX RX1512 versions prior to V2.16.0
RUGGEDCOM ROX RX1524 versions prior to V2.16.0
RUGGEDCOM ROX RX1536 versions prior to V2.16.0
RUGGEDCOM ROX RX5000 versions prior to V2.16.0
Description
A command injection vulnerability exists in the web interface of affected devices due to missing server-side input sanitation of the
software-upgrade Url parameter. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges. The vulnerability may enable a remote attacker to elevate their privileges and execute arbitrary commands.Recommendations
For RUGGEDCOM ROX MX5000 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX MX5000RE versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1400 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1500 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1501 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1510 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1511 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1512 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1524 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX1536 versions prior to V2.16.0, update to version V2.16.0 or later.
For RUGGEDCOM ROX RX5000 versions prior to V2.16.0, update to version V2.16.0 or later.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ruggedcom Rox Mx5000
Ruggedcom Rox Rx1400
Ruggedcom Rox Rx1500
Ruggedcom Rox Rx1501
Ruggedcom Rox Rx1510
Ruggedcom Rox Rx1511
Ruggedcom Rox Rx1512
Ruggedcom Rox Rx1524
Ruggedcom Rox Rx1536