Siemens RUGGEDCOM RST2428P
cpe:2.3:h:siemens:ruggedcom_rst2228p:*:*:*:*:*:*:*
- < V3.2
A vulnerability exists in several Siemens industrial communication devices running SINEC OS versions prior to 3.2. The issue lies in the web interface's session termination functionality, which has an incorrect authorization check. This flaw could enable an authenticated remote attacker with a 'guest' role to terminate the sessions of legitimate users.
Exploitation of this vulnerability allows an authenticated remote attacker with a 'guest' role to terminate the sessions of legitimate users, potentially disrupting their activities.
Siemens recommends updating to version 3.2 or later. For guidance on the update process, visit the Siemens Industry Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.