CVE-2024-56836: Command Injection
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56836?
CVE-2024-56836 is considered to be a medium severity vulnerability due to potential unauthorized configuration injections.
How do I fix CVE-2024-56836?
To fix CVE-2024-56836, upgrade the RUGGEDCOM ROX II software to version 2.17.0 or later.
What products are affected by CVE-2024-56836?
CVE-2024-56836 affects all versions of the RUGGEDCOM ROX II family prior to version 2.17.0.
What type of attack can exploit CVE-2024-56836?
CVE-2024-56836 can be exploited by attackers to inject additional configuration parameters via Dynamic DNS configuration.
When was CVE-2024-56836 published?
CVE-2024-56836 was published in 2024, detailing vulnerabilities in the RUGGEDCOM ROX II family.