CVE-2024-56837: Command Injection
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shell and gain root access on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56837?
CVE-2024-56837 is classified as a high severity vulnerability due to its potential to allow an attacker to gain root access.
How do I fix CVE-2024-56837?
To mitigate CVE-2024-56837, update RUGGEDCOM ROX II software to version 2.17.0 or later.
What impact does CVE-2024-56837 have on my system?
CVE-2024-56837 allows an attacker to spawn a reverse shell, potentially compromising system security and integrity.
Is my version of RUGGEDCOM ROX II affected by CVE-2024-56837?
Yes, all versions of RUGGEDCOM ROX II prior to 2.17.0 are affected by CVE-2024-56837.
Who is at risk from CVE-2024-56837?
Organizations using affected versions of RUGGEDCOM ROX II may be at risk of exploitation due to CVE-2024-56837.