OS Command Injection in Siemens products - CVE-2023-49691

 

OS Command Injection in Siemens products - CVE-2023-49691

Published: December 14, 2023


Vulnerability identifier: #VU84423
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49691
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the handling of the DDNS configuration. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

SCALANCE M874-3
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE WAM763-1
SCALANCE WAM766-1
SCALANCE WAM766-1 EEC
SCALANCE WUM763-1
SCALANCE WUM766-1
SCALANCE S615 EEC
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE S615
CALANCE M812-1 ADSL-Router (Annex A)

How to mitigate CVE-2023-49691

Install updates from vendor's website.

SCALANCE M874-3 - update to 8.0
SCALANCE S615 - update to 8.0
SCALANCE MUM856-1 (RoW) - update to 8.0
SCALANCE MUM856-1 (EU) - update to 8.0
SCALANCE MUM853-1 (EU) - update to 8.0
SCALANCE M876-4 (NAM) - update to 8.0
SCALANCE M876-4 (EU) - update to 8.0
SCALANCE M876-4 - update to 8.0
SCALANCE M876-3 (ROK) - update to 8.0
SCALANCE M876-3 (EVDO) - update to 8.0
RUGGEDCOM RM1224 LTE(4G) EU - update to 8.0
SCALANCE M874-2 - update to 8.0
SCALANCE M826-2 SHDSL-Router - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex B) - update to 8.0
SCALANCE M816-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex B) - update to 8.0
CALANCE M812-1 ADSL-Router (Annex A) - update to 8.0
SCALANCE M804PB - update to 8.0
RUGGEDCOM RM1224 LTE(4G) NAM - update to 8.0
SCALANCE S615 EEC - update to 8.0
SCALANCE M812-1 ADSL-Router (Annex A) - update to 8.0

External References

Related Security Bulletins