Siemens Ruggedcom Rox
This advisory details a vulnerability in Siemens Ruggedcom Rox devices due to improper input validation within the JSON-RPC interface. An authenticated remote attacker could potentially read arbitrary files from the device's filesystem with root privileges. Siemens has released updated versions (V2.17.1) to address this issue, and CISA recommends implementing defensive measures to minimize exploitation risk, including network segmentation and secure remote access methods.
The vulnerability stems from a flaw in the way the Siemens Ruggedcom Rox devices handle requests through their JSON-RPC interface. Specifically, the devices lack sufficient input validation, allowing a malicious, authenticated remote attacker to bypass security controls and gain access to the underlying operating system's file system. This access would grant the attacker root privileges, enabling them to potentially compromise the device and its associated network. Siemens has responded by releasing updated versions of the affected products, specifically versions RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, and RUGGEDCOM ROX RX5000, all updated to version 2.17.1 or later. CISA is advising organizations to immediately update their devices to mitigate this risk.