CVE Database
/

CVE-2024-50559

Back to search

CVE-2024-50559

Published: Nov 12, 2024

Modified: Nov 12, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V8.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V8.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V8.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.2), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.2), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.2), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.2), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.2), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.2), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.2). Affected devices do not properly validate the filenames of the certificate. This could allow an authenticated remote attacker to append arbitrary values which will lead to compromise of integrity of the system.

VendorProductVersions

Siemens

RUGGEDCOM RM1224 LTE(4G) EU

affected
0 - < V8.2

Siemens

RUGGEDCOM RM1224 LTE(4G) NAM

affected
0 - < V8.2

Siemens

SCALANCE M804PB

affected
0 - < V8.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V8.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V8.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V8.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V8.2

Siemens

SCALANCE M826-2 SHDSL-Router

affected
0 - < V8.2

Siemens

SCALANCE M874-2

affected
0 - < V8.2

Siemens

SCALANCE M874-3

affected
0 - < V8.2

Siemens

SCALANCE M874-3 3G-Router (CN)

affected
0 - < V8.2

Siemens

SCALANCE M876-3

affected
0 - < V8.2

Siemens

SCALANCE M876-3 (ROK)

affected
0 - < V8.2

Siemens

SCALANCE M876-4

affected
0 - < V8.2

Siemens

SCALANCE M876-4 (EU)

affected
0 - < V8.2

Siemens

SCALANCE M876-4 (NAM)

affected
0 - < V8.2

Siemens

SCALANCE MUM853-1 (A1)

affected
0 - < V8.2

Siemens

SCALANCE MUM853-1 (B1)

affected
0 - < V8.2

Siemens

SCALANCE MUM853-1 (EU)

affected
0 - < V8.2

Siemens

SCALANCE MUM856-1 (A1)

affected
0 - < V8.2

Siemens

SCALANCE MUM856-1 (B1)

affected
0 - < V8.2

Siemens

SCALANCE MUM856-1 (CN)

affected
0 - < V8.2

Siemens

SCALANCE MUM856-1 (EU)

affected
0 - < V8.2

Siemens

SCALANCE MUM856-1 (RoW)

affected
0 - < V8.2

Siemens

SCALANCE S615 EEC LAN-Router

affected
0 - < V8.2

Siemens

SCALANCE S615 LAN-Router

affected
0 - < V8.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now