ID

VAR-202512-0220


CVE

CVE-2024-56838


DESCRIPTION

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.

Trust: 1.0

sources: NVD: CVE-2024-56838

AFFECTED PRODUCTS

vendor:siemensmodel:ruggedcom rox iiscope:ltversion:2.17.0

Trust: 1.0

sources: NVD: CVE-2024-56838

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-56838
value: HIGH

Trust: 1.0

productcert@siemens.com: CVE-2024-56838
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2024-56838

PROBLEMTYPE DATA

problemtype:CWE-74

Trust: 1.0

sources: NVD: CVE-2024-56838

EXTERNAL IDS

db:SIEMENSid:SSA-912274

Trust: 1.0

db:NVDid:CVE-2024-56838

Trust: 1.0

sources: NVD: CVE-2024-56838

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-912274.html

Trust: 1.0

sources: NVD: CVE-2024-56838

SOURCES

db:NVDid:CVE-2024-56838

LAST UPDATE DATE

2026-01-14T23:31:03.749000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2024-56838date:2026-01-13T10:15:57.100

SOURCES RELEASE DATE

db:NVDid:CVE-2024-56838date:2025-12-09T16:17:29.120