QID 591224

Date Published: 2022-12-09

QID 591224: Siemens RUGGEDCOM ROX products Remote Code Execution (RCE) and Denial of Service (DoS) Vulnerability (SSA-594438)

AFFECTED PRODUCTS
RUGGEDCOM ROX MX5000: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1400: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1500: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1501: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1510: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1511: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1512: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1524: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX1536: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version
RUGGEDCOM ROX RX5000: All versions greater than or equal to V2.10.0 and less than V2.15.0, Update to V2.15.0 or later version

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

A vulnerability in the RUGGEDCOM ROX devices' third party component, NSS, could allow an attacker to remotely execute code or cause a denial-of-service condition due to the way it verifies security certificates. Siemens has released updates for the affected products and recommends to update to the latest versions

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-594438 for affected packages and patching details.

    CVEs related to QID 591224

    Software Advisories
    Advisory ID Software Component Link
    ssa-594438 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-594438.pdf