Il firmware ROX nasconde un lungo arretrato di CVE
Il vero problema non è un singolo bug Siemens. Il firmware ROX prima di V2.17.1 porta con sé un arretrato di vulnerabilità di terze parti, quindi una versione dell’appliance può poggiare su anni di esposizione latente invece che su un singolo problema correggibile. Questo rompe il consueto approccio di update per singolo CVE per gli apparati industrial edge.
Siemens Ruggedcom Rox Summary Ruggedcom Rox contains an input validation vulnerability in the feature key installation process that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Siemens Ruggedcom Rox Summary Ruggedcom Rox contains an improper access control vulnerability that could allow an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem.
Siemens Ruggedcom Rox Summary Ruggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.