CVE-2025-23384
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
CVE-2025-23384 is a vulnerability affecting multiple RUGGEDCOM and SCALANCE router models, including RM1224 LTE, M804PB, M812-1 ADSL-Router family, M816-1 ADSL-Router family, M826-2 SHDSL-Router, M874-2, M874-3, M876-3 (A1, B1, EU, NAM, RoW), M876-4 (EU, NAM), MUB852-1 (A1, B1), MUM853-1 (A1, B1, EU), MUM856-1 (A1, B1, CN, EU, RoW), and S615 EEC LAN-Router, S615 LAN-Router, and the SC-600 family. The affected devices have a flaw in their OpenVPN authentication process, allowing partial invalid usernames to be accepted by the server. An attacker could exploit this vulnerability to gain unauthorized access to the affected network. Users are advised to update their devices to version V8.2.1 or later to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Siemens AG