Siemens Ruggedcom Rox

Summary

Siemens Ruggedcom Rox devices contain an input validation vulnerability in the feature key installation process. This vulnerability could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions to address this issue.

IFF Assessment

FOE

The vulnerability allows for remote code execution with root privileges, posing a significant threat to the affected industrial systems.

Severity

7.5 High

The CVSS score of 7.5 reflects a high severity due to the 'OS Command Injection' vulnerability. The attack vector is network-based, and an attacker with authentication can gain root privileges, allowing for arbitrary command execution.

Defender Context

This vulnerability in Siemens Ruggedcom Rox devices highlights the ongoing risk of command injection in industrial control systems. Defenders should prioritize patching affected devices and ensure strong authentication mechanisms are in place for access to critical infrastructure components.

Read Full Story →