Siemens Ruggedcom Rox
Summary
Siemens Ruggedcom Rox devices are affected by an input validation vulnerability in the Scheduler functionality. This flaw could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released updated versions to address this critical vulnerability.
IFF Assessment
This vulnerability allows an authenticated remote attacker to gain root privileges on critical infrastructure devices, posing a significant threat to operational integrity.
Severity
A CVSS score of 9.1 indicates a critical vulnerability. The 'OS Command Injection' allows an authenticated remote attacker to execute arbitrary commands with root privileges, impacting confidentiality, integrity, and availability.
Defender Context
This advisory highlights a critical vulnerability in Siemens Ruggedcom Rox devices, commonly used in critical infrastructure. Defenders must prioritize patching or mitigating these devices immediately to prevent potential command injection and system compromise. The ease of exploitation by authenticated users underscores the need for robust access controls and continuous monitoring of industrial control systems.