Siemens RUGGEDCOM ROX MX5000
cpe:2.3:h:siemens:ruggedcom_rox_mx5000:*:*:*:*:*:*:*, +1 more
- < V2.17.1
A remote code execution vulnerability has been identified in several Ruggedcom ROX products, all versions prior to V2.17.1. The issue arises from improper input validation during the feature key installation process, which could enable an authenticated remote attacker to inject arbitrary commands. This exploitation would result in remote code execution with root privileges on the underlying operating system.
Exploitation of this vulnerability allows for remote code execution with root privileges on the affected device's operating system.
Siemens has released new versions for the affected products. Users are advised to update to the latest versions. For general security recommendations, Siemens suggests protecting network access to devices with appropriate measures and configuring the environment according to Siemens' operational guidelines for Industrial Security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.