CVE-2024-50572
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-50572 is a vulnerability affecting multiple RUGGEDCOM and SCALANCE device models, including RM1224 LTE(4G) EU and NAM, SCALANCE M804PB, M812-1 ADSL-Router, M816-1 ADSL-Router, M826-2 SHDSL-Router, M874-2, M874-3, M876-3, M876-4, MUM853-1, MUM856-1, and S615 LAN-Router. Versions prior to V8.2 are vulnerable. The issue stems from these devices failing to sanitize an input field, making them susceptible to code injection. Authenticated attackers with administrative privileges can capitalize on this vulnerability, resulting in the spawning of a system root shell.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Siemens AG