目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2023-52237— Siemens 多款产品信息泄露漏洞

CVSS 7.5 · High EPSS 0.15% · P35
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-52237の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
N/A
ソース: NVD (National Vulnerability Database)
脆弱性説明
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200NC, RUGGEDCOM M969, RUGGEDCOM M969NC, RUGGEDCOM RMC30, RUGGEDCOM RMC30NC, RUGGEDCOM RMC8388 V4.X, RUGGEDCOM RMC8388 V5.X, RUGGEDCOM RMC8388NC V4.X, RUGGEDCOM RMC8388NC V5.X, RUGGEDCOM RP110, RUGGEDCOM RP110NC, RUGGEDCOM RS1600, RUGGEDCOM RS1600F, RUGGEDCOM RS1600FNC, RUGGEDCOM RS1600NC, RUGGEDCOM RS1600T, RUGGEDCOM RS1600TNC, RUGGEDCOM RS400, RUGGEDCOM RS400NC, RUGGEDCOM RS401, RUGGEDCOM RS401NC, RUGGEDCOM RS416, RUGGEDCOM RS416NC, RUGGEDCOM RS416NCv2 V4.X, RUGGEDCOM RS416NCv2 V5.X, RUGGEDCOM RS416P, RUGGEDCOM RS416PNC, RUGGEDCOM RS416PNCv2 V4.X, RUGGEDCOM RS416PNCv2 V5.X, RUGGEDCOM RS416Pv2 V4.X, RUGGEDCOM RS416Pv2 V5.X, RUGGEDCOM RS416v2 V4.X, RUGGEDCOM RS416v2 V5.X, RUGGEDCOM RS8000, RUGGEDCOM RS8000A, RUGGEDCOM RS8000ANC, RUGGEDCOM RS8000H, RUGGEDCOM RS8000HNC, RUGGEDCOM RS8000NC, RUGGEDCOM RS8000T, RUGGEDCOM RS8000TNC, RUGGEDCOM RS900, RUGGEDCOM RS900 (32M) V4.X, RUGGEDCOM RS900 (32M) V5.X, RUGGEDCOM RS900G, RUGGEDCOM RS900G (32M) V4.X, RUGGEDCOM RS900G (32M) V5.X, RUGGEDCOM RS900GNC, RUGGEDCOM RS900GNC(32M) V4.X, RUGGEDCOM RS900GNC(32M) V5.X, RUGGEDCOM RS900GP, RUGGEDCOM RS900GPNC, RUGGEDCOM RS900L, RUGGEDCOM RS900LNC, RUGGEDCOM RS900M-GETS-C01, RUGGEDCOM RS900M-GETS-XX, RUGGEDCOM RS900M-STND-C01, RUGGEDCOM RS900M-STND-XX, RUGGEDCOM RS900MNC-GETS-C01, RUGGEDCOM RS900MNC-GETS-XX, RUGGEDCOM RS900MNC-STND-XX, RUGGEDCOM RS900MNC-STND-XX-C01, RUGGEDCOM RS900NC, RUGGEDCOM RS900NC(32M) V4.X, RUGGEDCOM RS900NC(32M) V5.X, RUGGEDCOM RS900W, RUGGEDCOM RS910, RUGGEDCOM RS910L, RUGGEDCOM RS910LNC, RUGGEDCOM RS910NC, RUGGEDCOM RS910W, RUGGEDCOM RS920L, RUGGEDCOM RS920LNC, RUGGEDCOM RS920W, RUGGEDCOM RS930L, RUGGEDCOM RS930LNC, RUGGEDCOM RS930W, RUGGEDCOM RS940G, RUGGEDCOM RS940GNC, RUGGEDCOM RS969, RUGGEDCOM RS969NC, RUGGEDCOM RSG2100, RUGGEDCOM RSG2100 (32M) V4.X, RUGGEDCOM RSG2100 (32M) V5.X, RUGGEDCOM RSG2100NC, RUGGEDCOM RSG2100NC(32M) V4.X, RUGGEDCOM RSG2100NC(32M) V5.X, RUGGEDCOM RSG2100P, RUGGEDCOM RSG2100P (32M) V4.X, RUGGEDCOM RSG2100P (32M) V5.X, RUGGEDCOM RSG2100PNC, RUGGEDCOM RSG2100PNC (32M) V4.X, RUGGEDCOM RSG2100PNC (32M) V5.X, RUGGEDCOM RSG2200, RUGGEDCOM RSG2200NC, RUGGEDCOM RSG2288 V4.X, RUGGEDCOM RSG2288 V5.X, RUGGEDCOM RSG2288NC V4.X, RUGGEDCOM RSG2288NC V5.X, RUGGEDCOM RSG2300 V4.X, RUGGEDCOM RSG2300 V5.X, RUGGEDCOM RSG2300NC V4.X, RUGGEDCOM RSG2300NC V5.X, RUGGEDCOM RSG2300P V4.X, RUGGEDCOM RSG2300P V5.X, RUGGEDCOM RSG2300PNC V4.X, RUGGEDCOM RSG2300PNC V5.X, RUGGEDCOM RSG2488 V4.X, RUGGEDCOM RSG2488 V5.X, RUGGEDCOM RSG2488NC V4.X, RUGGEDCOM RSG2488NC V5.X, RUGGEDCOM RSG907R, RUGGEDCOM RSG908C, RUGGEDCOM RSG909R, RUGGEDCOM RSG910C, RUGGEDCOM RSG920P V4.X, RUGGEDCOM RSG920P V5.X, RUGGEDCOM RSG920PNC V4.X, RUGGEDCOM RSG920PNC V5.X, RUGGEDCOM RSL910, RUGGEDCOM RSL910NC, RUGGEDCOM RST2228, RUGGEDCOM RST2228P, RUGGEDCOM RST916C, RUGGEDCOM RST916P. The web server of the affected devices allow a low privileged user to access hashes and password salts of all system's users, including admin users. An attacker could use the obtained information to brute force the passwords offline.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
信息暴露
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Siemens 多款产品信息泄露漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Siemens RUGGEDCOM Series是德国西门子(Siemens)公司的一系列工业通信设备。 Siemens 多款产品存在信息泄露漏洞,该漏洞源于受影响设备的 Web 服务器允许低权限用户访问所有系统用户(包括管理员用户)的哈希值和密码盐值。攻击者可以使用获取的信息在离线状态下强行破解密码。以下产品及版本受到影响:Siemens RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802,
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
SiemensRUGGEDCOM i800 0 ~ V4.3.10 -
SiemensRUGGEDCOM i800NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM i801 0 ~ V4.3.10 -
SiemensRUGGEDCOM i801NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM i802 0 ~ V4.3.10 -
SiemensRUGGEDCOM i802NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM i803 0 ~ V4.3.10 -
SiemensRUGGEDCOM i803NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM M2100 0 ~ V4.3.10 -
SiemensRUGGEDCOM M2100NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM M2200 0 ~ V4.3.10 -
SiemensRUGGEDCOM M2200NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM M969 0 ~ V4.3.10 -
SiemensRUGGEDCOM M969NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RMC30 0 ~ V4.3.10 -
SiemensRUGGEDCOM RMC30NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RMC8388 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RMC8388 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RMC8388NC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RMC8388NC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RP110 0 ~ V4.3.10 -
SiemensRUGGEDCOM RP110NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600F 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600FNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600T 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS1600TNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS400 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS400NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS401 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS401NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416NCv2 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416NCv2 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS416P 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416PNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416PNCv2 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416PNCv2 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS416Pv2 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416Pv2 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS416v2 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS416v2 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS8000 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000A 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000ANC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000H 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000HNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000T 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS8000TNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900 (32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900 (32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS900G 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900G (32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900G (32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS900GNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900GNC(32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900GNC(32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS900GP 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900GPNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900L 0 ~ * -
SiemensRUGGEDCOM RS900LNC 0 ~ * -
SiemensRUGGEDCOM RS900M-GETS-C01 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900M-GETS-XX 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900M-STND-C01 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900M-STND-XX 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900MNC-GETS-C01 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900MNC-GETS-XX 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900MNC-STND-XX 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900MNC-STND-XX-C01 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900NC(32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS900NC(32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RS900W 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS910 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS910L 0 ~ * -
SiemensRUGGEDCOM RS910LNC 0 ~ * -
SiemensRUGGEDCOM RS910NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS910W 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS920L 0 ~ * -
SiemensRUGGEDCOM RS920LNC 0 ~ * -
SiemensRUGGEDCOM RS920W 0 ~ * -
SiemensRUGGEDCOM RS930L 0 ~ * -
SiemensRUGGEDCOM RS930LNC 0 ~ * -
SiemensRUGGEDCOM RS930W 0 ~ * -
SiemensRUGGEDCOM RS940G 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS940GNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RS969 0 ~ * -
SiemensRUGGEDCOM RS969NC 0 ~ * -
SiemensRUGGEDCOM RSG2100 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100 (32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100 (32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2100NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100NC(32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100NC(32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2100P 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100P (32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100P (32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2100PNC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100PNC (32M) V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2100PNC (32M) V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2200 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2200NC 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2288 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2288 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2288NC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2288NC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2300 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2300 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2300NC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2300NC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2300P V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2300P V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2300PNC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2300PNC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2488 V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2488 V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG2488NC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG2488NC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG907R 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG908C 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG909R 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG910C 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG920P V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG920P V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSG920PNC V4.X 0 ~ V4.3.10 -
SiemensRUGGEDCOM RSG920PNC V5.X 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSL910 0 ~ V5.9.0 -
SiemensRUGGEDCOM RSL910NC 0 ~ V5.9.0 -
SiemensRUGGEDCOM RST2228 0 ~ V5.9.0 -
SiemensRUGGEDCOM RST2228P 0 ~ V5.9.0 -
SiemensRUGGEDCOM RST916C 0 ~ V5.9.0 -
SiemensRUGGEDCOM RST916P 0 ~ V5.9.0 -

II. CVE-2023-52237の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-52237のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Siemens · 2024-07-09 · 33 CVEs total

CVE-2024-398729.6 CRITICALSiemens SINEMA Remote Connect Server 安全漏洞
CVE-2024-395708.8 HIGHSiemens SINEMA Remote Connect Server 命令注入漏洞
CVE-2024-395718.8 HIGHSiemens SINEMA Remote Connect Server 安全漏洞
CVE-2024-398668.8 HIGHSiemens SINEMA Remote Connect 安全漏洞
CVE-2024-398658.8 HIGHSiemens SINEMA Remote Connect Server 代码问题漏洞
CVE-2024-396758.8 HIGHSiemens 多款产品安全漏洞
CVE-2022-451477.8 HIGHSiemens SIMATIC PCS和SIMATIC STEP 代码问题漏洞
CVE-2024-320567.8 HIGHSiemens Simcenter Femap 缓冲区错误漏洞
CVE-2024-395677.8 HIGHSiemens SINEMA Remote Connect 命令注入漏洞
CVE-2024-395687.8 HIGHSiemens SINEMA Remote Connect 命令注入漏洞
CVE-2024-336537.8 HIGHSiemens Simcenter Femap 缓冲区错误漏洞
CVE-2024-336547.8 HIGHSiemens Simcenter Femap 缓冲区错误漏洞
CVE-2024-379977.8 HIGHSiemens JT Open Toolkit 安全漏洞
CVE-2024-398677.6 HIGHSiemens SINEMA Remote Connect 安全漏洞
CVE-2024-398687.6 HIGHSiemens SINEMA Remote Connect Server 安全漏洞
CVE-2024-398887.5 HIGHSiemens Mendix 安全漏洞
CVE-2024-398737.5 HIGHSiemens SINEMA Remote Connect Server 安全漏洞
CVE-2024-398747.5 HIGHSiemens SINEMA Remote Connect 安全漏洞
CVE-2024-395696.6 MEDIUMSiemens SINEMA Remote Connect Client 命令注入漏洞
CVE-2024-382786.6 MEDIUMSiemens RUGGEDCOM 安全漏洞

Showing 20 of 33 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2023-52237へのコメント

まだコメントはありません


コメントを残す