CVE-2020-28398: CSRF
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The CLI feature in the web interface of affected devices is vulnerable to cross-site request forgery (CSRF). This could allow an attacker to read or modify the device configuration by tricking an authenticated legitimate user into accessing a malicious link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28398?
CVE-2020-28398 has been assigned a severity rating that indicates it poses a significant risk, particularly on older versions of the affected RUGGEDCOM products.
Which RUGGEDCOM versions are affected by CVE-2020-28398?
CVE-2020-28398 affects all versions of RUGGEDCOM ROX MX5000, ROX MX5000RE, ROX RX1400, ROX RX1500, ROX RX1501, ROX RX1510 and others that are below version 2.16.0.
How can I fix CVE-2020-28398?
To mitigate CVE-2020-28398, upgrade the affected RUGGEDCOM devices to version 2.16.0 or later.
What type of vulnerability is CVE-2020-28398?
CVE-2020-28398 is identified as a security vulnerability in specific RUGGEDCOM products, primarily related to software flaws.
Is there a specific mitigation strategy for CVE-2020-28398?
The primary mitigation strategy for CVE-2020-28398 is to promptly update your RUGGEDCOM products to the latest available version.