PT-2021-21549 · Siemens · Ruggedcom Rox Rx1512+8
Published
2021-09-14
·
Updated
2021-12-14
·
CVE-2021-37173
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM ROX MX5000 versions prior to V2.14.1
RUGGEDCOM ROX RX1400 versions prior to V2.14.1
RUGGEDCOM ROX RX1500 versions prior to V2.14.1
RUGGEDCOM ROX RX1501 versions prior to V2.14.1
RUGGEDCOM ROX RX1510 versions prior to V2.14.1
RUGGEDCOM ROX RX1511 versions prior to V2.14.1
RUGGEDCOM ROX RX1512 versions prior to V2.14.1
RUGGEDCOM ROX RX1524 versions prior to V2.14.1
RUGGEDCOM ROX RX1536 versions prior to V2.14.1
RUGGEDCOM ROX RX5000 versions prior to V2.14.1
Description
The command line interface of affected devices insufficiently restricts file read and write operations for low-privileged users. This could allow an authenticated remote attacker to escalate privileges and gain root access to the device. The affected devices have an exposure of sensitive information vulnerability, which if exploited, could allow an authenticated attacker to extract data via Secure Shell (SSH).
Recommendations
For RUGGEDCOM ROX MX5000 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1400 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1500 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1501 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1510 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1511 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1512 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1524 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX1536 versions prior to V2.14.1, update to version V2.14.1 or later.
For RUGGEDCOM ROX RX5000 versions prior to V2.14.1, update to version V2.14.1 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruggedcom Rox Mx5000
Ruggedcom Rox Rx1400
Ruggedcom Rox Rx1500
Ruggedcom Rox Rx1501
Ruggedcom Rox Rx1510
Ruggedcom Rox Rx1511
Ruggedcom Rox Rx1512
Ruggedcom Rox Rx1524
Ruggedcom Rox Rx1536