CVE-2023-36751
published 2023-07-11CVE-2023-36751: A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400…
PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.54%
72.0th percentile
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The install-app URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | ruggedcom_rox_mx5000 | — | — |
| siemens | ruggedcom_rox_mx5000_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_mx5000re | — | — |
| siemens | ruggedcom_rox_mx5000re_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1400 | — | — |
| siemens | ruggedcom_rox_rx1400_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1500 | — | — |
| siemens | ruggedcom_rox_rx1500_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1501 | — | — |
| siemens | ruggedcom_rox_rx1501_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1510 | — | — |
| siemens | ruggedcom_rox_rx1510_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1511 | — | — |
| siemens | ruggedcom_rox_rx1511_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1512 | — | — |
| siemens | ruggedcom_rox_rx1512_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1524 | — | — |
| siemens | ruggedcom_rox_rx1524_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx1536 | — | — |
| siemens | ruggedcom_rox_rx1536_firmware | < 2.16.0 | 2.16.0 |
| siemens | ruggedcom_rox_rx5000 | — | — |
| siemens | ruggedcom_rox_rx5000_firmware | < 2.16.0 | 2.16.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX
cisa_ics·2023-07-13
Siemens RUGGEDCOM ROX
ICS Advisory
##
Siemens RUGGEDCOM ROX
Release DateJuly 13, 2023
Alert CodeICSA-23-194-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX
- Vulnerabilities: Cleartext Transmission of Sensitive Information, Command Injection, Improper Authentication, Classic Buffer Overflow, Uncontrolled Resource Consumption, Improper Certificate Validation, Cross-Site Request Forgery (CSRF), Improper Input Validation, Incorrect Default Permissions, Cross-site Scripting, Inadequate Encryption Strength, Use of a Broken or Risky Cryptographic Algorithm.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to send a malformed HTTP packet c
GHSA
GHSA-m988-f2xj-5386: A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2
ghsa_unreviewed·2023-07-11
CVE-2023-36751 [HIGH] CWE-77 GHSA-m988-f2xj-5386: A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The install-app URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published