CVE-2024-56840
- EPSS 0.07%
- Veröffentlicht 09.12.2025 10:44:19
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.
CVE-2024-56839
- EPSS 0.07%
- Veröffentlicht 09.12.2025 10:44:18
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitr...
CVE-2024-56838
- EPSS 0.04%
- Veröffentlicht 09.12.2025 10:44:17
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario ...
CVE-2024-56837
- EPSS 0.04%
- Veröffentlicht 09.12.2025 10:44:15
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shel...
CVE-2024-56836
- EPSS 0.05%
- Veröffentlicht 09.12.2025 10:44:14
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attack...
CVE-2024-56835
- EPSS 0.05%
- Veröffentlicht 09.12.2025 10:44:13
- Zuletzt bearbeitet 09.12.2025 18:37:13
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell ...