CVE Database
/

CVE-2023-49692

Back to search

CVE-2023-49692

Published: Dec 12, 2023

Modified: Aug 13, 2024

PUBLISHED

CVSS v3.1

7.2

HIGH

Description

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V7.2.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V7.2.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V7.2.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V7.2.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V7.2.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V7.2.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V7.2.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V7.2.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V7.2.2). An Improper Neutralization of Special Elements used in an OS Command with root privileges vulnerability exists in the parsing of the IPSEC configuration. This could allow malicious local administrators to issue commands on system level after a new connection is established.

VendorProductVersions

Siemens

RUGGEDCOM RM1224 LTE(4G) EU

affected
0 - < V7.2.2

Siemens

RUGGEDCOM RM1224 LTE(4G) NAM

affected
0 - < V7.2.2

Siemens

SCALANCE M804PB

affected
0 - < V7.2.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V7.2.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V7.2.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V7.2.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V7.2.2

Siemens

SCALANCE M826-2 SHDSL-Router

affected
0 - < V7.2.2

Siemens

SCALANCE M874-2

affected
0 - < V7.2.2

Siemens

SCALANCE M874-3

affected
0 - < V7.2.2

Siemens

SCALANCE M876-3

affected
0 - < V7.2.2

Siemens

SCALANCE M876-3 (ROK)

affected
0 - < V7.2.2

Siemens

SCALANCE M876-4

affected
0 - < V7.2.2

Siemens

SCALANCE M876-4 (EU)

affected
0 - < V7.2.2

Siemens

SCALANCE M876-4 (NAM)

affected
0 - < V7.2.2

Siemens

SCALANCE MUM853-1 (EU)

affected
0 - < V7.2.2

Siemens

SCALANCE MUM856-1 (EU)

affected
0 - < V7.2.2

Siemens

SCALANCE MUM856-1 (RoW)

affected
0 - < V7.2.2

Siemens

SCALANCE S615 EEC LAN-Router

affected
0 - < V7.2.2

Siemens

SCALANCE S615 LAN-Router

affected
0 - < V7.2.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now