A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices do not properly enforce isolation between user sessions in their web server component. This could allow an authenticated remote attacker to escalate their privileges on the devices.
History

Fri, 23 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens ruggedcom Rm1224 Lte\(4g\) Eu
Siemens ruggedcom Rm1224 Lte\(4g\) Eu Firmware
Siemens ruggedcom Rm1224 Lte\(4g\) Nam
Siemens ruggedcom Rm1224 Lte\(4g\) Nam Firmware
Siemens scalance M804pb
Siemens scalance M804pb Firmware
Siemens scalance M812-1 \(annex A\)
Siemens scalance M812-1 \(annex A\) Firmware
Siemens scalance M812-1 \(annex B\)
Siemens scalance M812-1 \(annex B\) Firmware
Siemens scalance M816-1 \(annex A\)
Siemens scalance M816-1 \(annex A\) Firmware
Siemens scalance M816-1 \(annex B\)
Siemens scalance M816-1 \(annex B\) Firmware
Siemens scalance M826-2 Shdsl-router
Siemens scalance M826-2 Shdsl-router Firmware
Siemens scalance M874-2
Siemens scalance M874-2 Firmware
Siemens scalance M874-3
Siemens scalance M874-3 3g-router \(cn\)
Siemens scalance M874-3 3g-router \(cn\) Firmware
Siemens scalance M874-3 Firmware
Siemens scalance M876-3
Siemens scalance M876-3 \(rok\)
Siemens scalance M876-3 \(rok\) Firmware
Siemens scalance M876-3 Firmware
Siemens scalance M876-4
Siemens scalance M876-4 \(eu\)
Siemens scalance M876-4 \(eu\) Firmware
Siemens scalance M876-4 \(nam\)
Siemens scalance M876-4 \(nam\) Firmware
Siemens scalance M876-4 Firmware
Siemens scalance Mum853-1 \(a1\)
Siemens scalance Mum853-1 \(a1\) Firmware
Siemens scalance Mum853-1 \(b1\)
Siemens scalance Mum853-1 \(b1\) Firmware
Siemens scalance Mum853-1 \(eu\)
Siemens scalance Mum853-1 \(eu\) Firmware
Siemens scalance Mum856-1 \(a1\)
Siemens scalance Mum856-1 \(a1\) Firmware
Siemens scalance Mum856-1 \(b1\)
Siemens scalance Mum856-1 \(b1\) Firmware
Siemens scalance Mum856-1 \(cn\)
Siemens scalance Mum856-1 \(cn\) Firmware
Siemens scalance Mum856-1 \(eu\)
Siemens scalance Mum856-1 \(eu\) Firmware
Siemens scalance Mum856-1 \(row\)
Siemens scalance Mum856-1 \(row\) Firmware
Siemens scalance S615 Eec Lan-router
Siemens scalance S615 Eec Lan-router Firmware
Siemens scalance S615 Lan-router
Siemens scalance S615 Lan-router Firmware
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:h:siemens:ruggedcom_rm1224_lte\(4g\)_eu:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rm1224_lte\(4g\)_nam:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m804pb:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m812-1_\(annex_a\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m812-1_\(annex_b\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m816-1_\(annex_a\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m816-1_\(annex_b\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m826-2_shdsl-router:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m874-2:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m874-3:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m874-3_3g-router_\(cn\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m876-3:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m876-3_\(rok\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m876-4:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m876-4_\(eu\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m876-4_\(nam\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum853-1_\(a1\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum853-1_\(b1\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum853-1_\(eu\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum856-1_\(a1\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum856-1_\(b1\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum856-1_\(cn\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum856-1_\(eu\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_mum856-1_\(row\):-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_s615_eec_lan-router:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_s615_lan-router:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rm1224_lte\(4g\)_eu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rm1224_lte\(4g\)_nam_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m804pb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m812-1_\(annex_a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m812-1_\(annex_b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m816-1_\(annex_a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m816-1_\(annex_b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m826-2_shdsl-router_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m874-2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m874-3_3g-router_\(cn\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m874-3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m876-3_\(rok\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m876-3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m876-4_\(eu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m876-4_\(nam\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m876-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum853-1_\(a1\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum853-1_\(b1\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum853-1_\(eu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum856-1_\(a1\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum856-1_\(b1\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum856-1_\(cn\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum856-1_\(eu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_mum856-1_\(row\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_s615_eec_lan-router_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_s615_lan-router_firmware:*:*:*:*:*:*:*:*
Vendors & Products Siemens ruggedcom Rm1224 Lte\(4g\) Eu
Siemens ruggedcom Rm1224 Lte\(4g\) Eu Firmware
Siemens ruggedcom Rm1224 Lte\(4g\) Nam
Siemens ruggedcom Rm1224 Lte\(4g\) Nam Firmware
Siemens scalance M804pb
Siemens scalance M804pb Firmware
Siemens scalance M812-1 \(annex A\)
Siemens scalance M812-1 \(annex A\) Firmware
Siemens scalance M812-1 \(annex B\)
Siemens scalance M812-1 \(annex B\) Firmware
Siemens scalance M816-1 \(annex A\)
Siemens scalance M816-1 \(annex A\) Firmware
Siemens scalance M816-1 \(annex B\)
Siemens scalance M816-1 \(annex B\) Firmware
Siemens scalance M826-2 Shdsl-router
Siemens scalance M826-2 Shdsl-router Firmware
Siemens scalance M874-2
Siemens scalance M874-2 Firmware
Siemens scalance M874-3
Siemens scalance M874-3 3g-router \(cn\)
Siemens scalance M874-3 3g-router \(cn\) Firmware
Siemens scalance M874-3 Firmware
Siemens scalance M876-3
Siemens scalance M876-3 \(rok\)
Siemens scalance M876-3 \(rok\) Firmware
Siemens scalance M876-3 Firmware
Siemens scalance M876-4
Siemens scalance M876-4 \(eu\)
Siemens scalance M876-4 \(eu\) Firmware
Siemens scalance M876-4 \(nam\)
Siemens scalance M876-4 \(nam\) Firmware
Siemens scalance M876-4 Firmware
Siemens scalance Mum853-1 \(a1\)
Siemens scalance Mum853-1 \(a1\) Firmware
Siemens scalance Mum853-1 \(b1\)
Siemens scalance Mum853-1 \(b1\) Firmware
Siemens scalance Mum853-1 \(eu\)
Siemens scalance Mum853-1 \(eu\) Firmware
Siemens scalance Mum856-1 \(a1\)
Siemens scalance Mum856-1 \(a1\) Firmware
Siemens scalance Mum856-1 \(b1\)
Siemens scalance Mum856-1 \(b1\) Firmware
Siemens scalance Mum856-1 \(cn\)
Siemens scalance Mum856-1 \(cn\) Firmware
Siemens scalance Mum856-1 \(eu\)
Siemens scalance Mum856-1 \(eu\) Firmware
Siemens scalance Mum856-1 \(row\)
Siemens scalance Mum856-1 \(row\) Firmware
Siemens scalance S615 Eec Lan-router
Siemens scalance S615 Eec Lan-router Firmware
Siemens scalance S615 Lan-router
Siemens scalance S615 Lan-router Firmware

Tue, 13 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens ruggedcom Rcm1224 Firmware
CPEs cpe:2.3:o:siemens:ruggedcom_rcm1224_firmware:6.2:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens ruggedcom Rcm1224 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices do not properly enforce isolation between user sessions in their web server component. This could allow an authenticated remote attacker to escalate their privileges on the devices.
Weaknesses CWE-488
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-08-13T07:54:37.591Z

Updated: 2024-08-13T16:01:41.802Z

Reserved: 2024-07-25T11:00:11.939Z

Link: CVE-2024-41977

cve-icon Vulnrichment

Updated: 2024-08-13T16:00:36.090Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-13T08:15:15.640

Modified: 2024-08-23T18:39:13.990

Link: CVE-2024-41977

cve-icon Redhat

No data.