QID 590978

Date Published: 2022-08-12

QID 590978: Siemens RUGGEDCOM ROX Vulnerability (ICSA-22-195-05) (SSA-599506)

AFFECTED PRODUCTS
The following Siemens products are affected:
RUGGEDCOM ROX MX5000: All versions prior to 2.15.1
RUGGEDCOM ROXMX5000RE: All versions prior to 2.15.1
RUGGEDCOM ROX RX1400: All versions prior to 2.15.1
RUGGEDCOM ROX RX1500: All versions prior to 2.15.1
RUGGEDCOM ROX RX1501: All versions prior to 2.15.1
RUGGEDCOM ROX RX1510: All versions prior to 2.15.1
RUGGEDCOM ROX RX1511: All versions prior to 2.15.1
RUGGEDCOM ROX RX1512: All versions prior to 2.15.1
RUGGEDCOM ROX RX1524: All versions prior to 2.15.1
RUGGEDCOM ROX RX1536: All versions prior to 2.15.1
RUGGEDCOM ROX RX5000: All versions prior to 2.15.1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker with administrative privileges to gain root access.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-195-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590978

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-195-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-195-05