QID 591187

Date Published: 2022-11-18

QID 591187: Siemens RUGGEDCOM ROS (Update A) Vulnerability (ICSA-22-195-18, SSA-840800)

AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following RUGGEDCOM ROS-based devices:
i800: All versions
i801: All versions
i802: All versions
i803: All versions
M969: All versions
M2100: All versions
M2200: All versions
RMC: All versions
RMC20: All versions
RMC30: All versions
RMC40: All versions
RMC41: All versions
RMC8388: All versions prior to v5.6.0
RP110: All versions
RS400: All versions
RS401: All versions
RS416: All versions
RS416v2: All versions prior to v5.6.0
RS900 (32M): All versions prior to v5.6.0
RS900G: All versions
RS900G (32M): All versions prior to v5.6.0
RS900GP: All versions
RS900L: All versions
RS900W: All versions
RS910: All versions
RS910L: All versions
RS910W: All versions
RS920L: All versions
RS920W: All versions
RS930L: All versions
RS930W: All versions
RS940G: All versions
RS969: All versions
RS900: All versions
RS1600: All versions
RS1600F: All versions
RS1600T: All versions
RS8000: All versions
RS8000A: All versions
RS8000H: All versions
RS8000T: All versions
RSG907R: All versions prior to v5.6.0
RSG908C: All versions prior to v5.6.0
RSG909R: All versions prior to v5.6.0
RSG910C: All versions prior to v5.6.0
RSG920P: All versions prior to v5.6.0
RSG2100: All versions
RSG2100 (32M): All versions prior to v5.6.0
RSG2100P: All versions
RSG2200: All versions
RSG2288: All versions prior to v5.6.0
RSG2300: All versions prior to v5.6.0
RSG2300P: All versions prior to v5.6.0
RSG2488: All versions prior to v5.6.0
RSL910: All versions prior to v5.6.0
RST916C: All versions prior to v5.6.0
RST916P: All versions prior to v5.6.0
RST2228: All versions prior to v5.6.0
RST2228P: All versions prior to v5.6.0

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could cause malicious behavior through legitimate user accounts accessing certain web resources on affected devices.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-195-18 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591187

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-195-18 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-195-18