PT-2023-9248 · Siemens · Ruggedcom Rst2228
Thomas Riedmaier
·
Published
2023-12-29
·
Updated
2024-07-09
·
CVE-2023-52238
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM RST2228 versions prior to V5.9.0
RUGGEDCOM RST2228P versions prior to V5.9.0
Description
A vulnerability has been identified in the web server of the affected systems, which leaks the MACSEC key in clear text to a logged-in user. This could allow an attacker with low-privileged user credentials to retrieve the MACSEC key and access (decrypt) the ethernet frames sent by authorized recipients. The issue is related to inadequate access control in the Ethernet Frame Handler component of the RUGGEDCOM Ethernet switch microprogram software, which may enable a remote attacker to gain unauthorized access to protected information.
Recommendations
For RUGGEDCOM RST2228 versions prior to V5.9.0, update to version V5.9.0 or later to resolve the issue.
For RUGGEDCOM RST2228P versions prior to V5.9.0, update to version V5.9.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the web server of the affected systems to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruggedcom Rst2228