ZeroHour

CVE-2022-46140

CVSS 4.0
7.1 high
EPSS
<1%p14
Published
()
Modified
Description

Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.

Vendors
siemens
Products
ruggedcom rm1224 lte\(4g\) eu firmware, ruggedcom rm1224 lte\(4g\) nam firmware, scalance m804pb firmware, scalance m812-1 adsl-router firmware, scalance m816-1 adsl-router firmware, scalance m826-2 shdsl-router firmware, scalance m874-2 firmware, scalance m874-3 firmware, scalance m876-3 firmware, scalance m876-4 firmware, scalance mum853-1 firmware, scalance mum856-1 firmware
Weakness
CWE-327
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.