CVE-2024-56840: Code Injection
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56840?
CVE-2024-56840 is considered a critical vulnerability due to its potential for allowing arbitrary code execution with root privileges.
How do I fix CVE-2024-56840?
To mitigate CVE-2024-56840, upgrade RUGGEDCOM ROX II to version 2.17.0 or later.
What devices are affected by CVE-2024-56840?
CVE-2024-56840 affects all versions of the RUGGEDCOM ROX II family prior to version 2.17.0.
What type of attack is possible with CVE-2024-56840?
An attacker could exploit CVE-2024-56840 to perform code injection, leading to arbitrary code execution.
Is there a workaround for CVE-2024-56840?
There is no known workaround for CVE-2024-56840; upgrading to a fixed version is the only solution.