Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g84-v2xm-86jp

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.

EPSS

Процентиль: 18%
0.00056
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.2
nvd
9 дней назад

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.

CVSS3: 7.2
fstec
9 дней назад

Уязвимость реализации протокола Simple Certificate Enrollment Protocol (SCEP) микропрограммного обеспечения платформ маршрутизации и коммутации RUGGEDCOM ROX II, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 18%
0.00056
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-74