CVE-2023-44317

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Nov 14, 2023
Updated: Jan 14, 2025
CWE ID 349

Summary

CVE-2023-44317 is a vulnerability affecting multiple SCALANCE and RUGGEDCOM devices, including RM1224 LTE routers, M804PB, M812-1 ADSL-Routers, M816-1 ADSL-Routers, M826-2 SHDSL-Routers, M874-2, M874-3, M876-3, M876-4, MUM853-1, MUM856-1, S615 LAN-Routers, WAB762-1, WAM763-1, WAM766-1, WUB762-1, and WUM763-1. These devices fail to adequately validate the content of uploaded X509 certificates, enabling attackers with administrative privileges to execute arbitrary code on the devices. All versions of the affected products prior to V7.2.2 (for routers) and V3.0.0 (for other devices) are susceptible to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Siemens SCALANCE XF204

Affected Vendors

  • Siemens AG