Siemens RUGGEDCOM ROX MX5000
cpe:2.3:h:siemens:ruggedcom_rox_mx5000:*:*:*:*:*:*:*, +1 more
- < V2.16.5
A command injection vulnerability has been identified in the web interface of several RUGGEDCOM ROX II devices, all versions prior to 2.16.5. The issue arises in the 'tcpdump' tool, which is vulnerable due to inadequate server-side input validation. This flaw could enable an authenticated remote attacker to execute arbitrary code with root privileges on the affected device.
Exploitation of this vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on the affected device.
Users are advised to update to version 2.16.5 or later. For more information, visit the Siemens Industry Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.