PT-2024-8712 · Siemens · Scalance M812-1 Adsl-Router+13

Published

2024-11-12

·

Updated

2024-11-13

·

CVE-2024-50559

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RUGGEDCOM RM1224 LTE(4G) EU versions < V8.2 RUGGEDCOM RM1224 LTE(4G) NAM versions < V8.2 SCALANCE M804PB versions < V8.2 SCALANCE M812-1 ADSL-Router versions < V8.2 SCALANCE M816-1 ADSL-Router versions < V8.2 SCALANCE M826-2 SHDSL-Router versions < V8.2 SCALANCE M874-2 versions < V8.2 SCALANCE M874-3 versions < V8.2 SCALANCE M874-3 3G-Router (CN) versions < V8.2 SCALANCE M876-3 versions < V8.2 SCALANCE M876-3 (ROK) versions < V8.2 SCALANCE M876-4 versions < V8.2 SCALANCE M876-4 (EU) versions < V8.2 SCALANCE M876-4 (NAM) versions < V8.2 SCALANCE MUM853-1 versions < V8.2 SCALANCE MUM856-1 versions < V8.2 SCALANCE S615 EEC LAN-Router versions < V8.2 SCALANCE S615 LAN-Router versions < V8.2
Description The affected devices do not properly validate the filenames of the certificate, which could allow an authenticated remote attacker to append arbitrary values, leading to a compromise of the system's integrity. This issue is related to incorrect restriction of the path name to a directory with limited access.
Recommendations For all versions < V8.2, update to version V8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available. Avoid using the vulnerable functionality until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-10314
CVE-2024-50559

Affected Products

Ruggedcom Rm1224 Lte(4G) Eu
Ruggedcom Rm1224 Lte(4G) Nam
Scalance M804Pb
Scalance M812-1 Adsl-Router
Scalance M816-1 Adsl-Router
Scalance M826-2 Shdsl-Router
Scalance M874-2
Scalance M874-3
Scalance M874-3 3G-Router
Scalance M876-3
Scalance M876-4
Scalance Mum853-1
Scalance Mum856-1
Scalance S615 Eec Lan-Router