2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-39158" ,
"sourceIdentifier" : "productcert@siemens.com" ,
"published" : "2022-09-13T10:15:12.087" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:17:41.447" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
2023-11-14 13:00:21 +00:00
"value" : "Affected devices improperly handle partial HTTP requests which makes them vulnerable to slowloris attacks. \r\n\r\nThis could allow a remote attacker to create a denial of service condition that persists until the attack ends."
2023-04-24 12:24:31 +02:00
} ,
{
"lang" : "es" ,
2023-11-14 13:00:21 +00:00
"value" : " S e h a i d e n t i f i c a d o u n a v u l n e r a b i l i d a d e n \ n R U G G E D C O M i 800 , \ n R U G G E D C O M i 800 N C , \ n R U G G E D C O M i 801 , \ n R U G G E D C O M i 801 N C , \ n R U G G E D C O M i 802 , \ n R U G G E D C O M i 802 N C , \ n R U G G E D C O M i 803 , \ n R U G G E D C O M i 803 N C , \ n R U G G E D C O M M 2100 , \ n R U G G E D C O M M 2100 F , \ n R U G G E D C O M M 210 0 N C , \ n R U G G E D C O M M 2200 , \ n R U G G E D C O M M 2200 F , \ n R U G G E D C O M M 2200 N C , \ n R U G G E D C O M M 969 , \ n R U G G E D C O M M 969 F , \ n R U G G E D C O M M 969 N C , \ n R U G G E D C O M R M C 30 , \ n R U G G E D C O M R M C 30 N C , \ n R U G G E D C O M R M C 8388 V 4 . X , \ n R U G G E D C O M R M C 8388 V 5 . X , \ n R U G G E D C O M R M C 8388 N C V 4 . X , \ n R U G G E D C O M R M C 8388 N C V 5 . X , \ n R U G G E D C O M R M C 8388 N C V 5 . X , \ n R U G G E D C O M R P 110 , \ n R U G G E D C O M R P 110 N C , \ n R U G G E D C O M R S 1600 , \ n R U G G E D C O M R S 1600 F , \ n R U G G E D C O M R S 1600 F N C , \ n R U G G E D C O M R S 1600 N C , \ n R U G G E D C O M R S 1600 T , \ n R U G G E D C O M R S 1600 T N C , \ n R U G G E D C O M R S 400 , \ n R U G G E D C O M R S 400 F , \ n R U G G E D C O M R S 400 N C , \ n R U G G E D C O M R S 401 , \ n R U G G E D C O M R S 401 N C , \ n R U G G E D C O M R S 416 , \ n R U G G E D C O M R S 416 F , \ n R U G G E D C O M R S 416 N C , \ n R U G G E D C O M R S 416 N C v 2 , \ n R U G G E D C O M R S 416 N C v 2 , \ n R U G G E D C O M R S 416 P , \ n R U G G E D C O M R S 416 P F , \ n R U G G E D C O M R S 416 P N C , \ n R U G G E D C O M R S 416 P N C v 2 , \ n R U G G E D C O M R S 416 P N C v 2 , \ n R U G G E D C O M R S 416 P v 2 , \ n R U G G E D C O M R S 416 v 2 , \ n R U G G E D C O M R S 8000 , \ n R U G G E D C O M R S 8000 A , \ n R U G G E D C O M R S 8000 A N C , \ n R U G G E D C O M R S 8000 H , \ n R U G G E D C O M R S 8000 H N C , \ n R U G G E D C O M R S 8000 N C , \ n R U G G E D C O M R S 8000 T , \ n R U G G E D C O M R S 8000 T N C , \ n R U G G E D C O M R S 900 , \ n R U G G E D C O M R S 900 ( 32 M ) V 4 . X , \ n R U G G E D C O M R S 900 ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 F , \ n R U G G E D C O M R S 900 G , \ n R U G G E D C O M R S 900 G ( 32 M ) V 4 . X , \ n R U G G E D C O M R S 900 G ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 G F , \ n R U G G E D C O M R S 900 G N C , \ n R U G G E D C O M R S 900 G N C ( 32 M ) V 4 . X , \ n R U G G E D C O M R S 900 G N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 G N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 G P , \ n R U G G E D C O M R S 900 G P F , \ n R U G G E D C O M R S 900 G P N C , \ n R U G G E D C O M R S 900 L , \ n R U G G E D C O M R S 900 L N C , \ n R U G G E D C O M R S 900 M - G E T S - C 0 1 , \ n R U G G E D C O M R S 900 M - G E T S - X x , \ n r u g g e d c o m r s 900 m - s t n d - c 0 1 , \ n r u g g e d c o m r s 900 m - s t n d - x x , \ n r u g g e d c o m r s 900 m n c - g e t s - c 0 1 , \ n r u g g e d c o m r s 900 m n c - g e t s - x x , \ n r s 900 m n c - s t n d - x x , \ n r s 900 m n c - s t n d - x x c . C o m , \ n r s 900 m n c - s t n d - x x , \ n r s u g u g e d c o m r s 900 m n c - s t n d - x x c , \ n r s 900 m n c - s t n d - x x , \ n r s u g u g e d c o m r s 900 m n c - s t n d - x x c c , \ n R U G G E D C O M R S 900 N C ( 32 M ) V 4 . X , \ n R U G G E D C O M R S 900 N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S 900 W , \ n R U G G E D C O M R S 910 , \ n R U G G E D C O M R S 910 L , \ n R U G G E D C O M R S 910 L N C , \ n R U G G E D C O M R S 910 N C , \ n R U G G E D C O M R S 910 W , \ n R U G G E D C O M R S 920 L , \ n R U G G E D C O M R S 920 L N C , \ n R U G G E D C O M R S 920 W , \ n R U G G E D C O M R S 930 L , \ n R U G G E D C O M R S 930 L N C , \ n R U G G E D C O M R S 930 W , \ n R U G G E D C O M R S 940 G , \ n R U G G E D C O M R S 940 G F , \ n R U G G E D C O M R S 940 G N C , \ n R U G G E D C O M R S 969 , \ n R U G G E D C O M R S 969 N C , \ n R U G G E D C O M R S G 2100 , \ n R U G G E D C O M R S G 2100 ( 32 M ) V 4 . X , \ n R U G G E D C O M R S G 2100 ( 32 M ) V 5 . X , \ n R U G G E D C O M R S G 2100 F , \ n R U G G E D C O M R S G 2100 N C , \ n R U G G E D C O M R S G 2100 N C ( 32 M ) V 4 . X , \ n R U G G E D C O M R S G 2100 N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S G 2100 N C ( 32 M ) V 5 . X , \ n R U G G E D C O M R S G 2100 P , \ n R U G G E D C O M R S G 2100 P F , \ n R U G G E D C O M R S G 2100 P N C , \ n R U G G E D C O M R S G 2200 , \ n R U G G E D C O M R S G 2200 F , \ n R U G G E D C O M R S G 2200 N C , \ n R U G G E D C O M R S G 2288 V 4 . X , \ n R U G G E D C O M R S G 2288 V 5 . X , \ n R U G G E D C O M R S G 2288 N C V 4 . X , \ n R U G G E D C O M R S G 2288 N C V 5 . X , \ n R U G G E D C O M R S G 2288 N C V 5 . X , \ n R U G G E D C O M R S G 2300 V 4 . X , \ n R U G G E D C O M R S G 2300 V 5 . X , \ n R U G G E D C O M R S G 2300 F , \ n R U G G E D C O M R S G 2300 N C V 4 . X , \ n R U G G E D C O M R S G 2300 N C V 5 . X , \ n R U G G E D C O M R S G 2300 N C V 5 . X , \ n R U G G E D C O M R S G 2300 P V 4 . X , \ n R U G G E D C O M R S G 2300 P V 5 . X , \ n R U G G E D C O M R S G 2300 P F , \ n R U G G E D C O M R S G 2300 P N C V 4 . X , \ n R U G G E D C O M R S G 2300 P N C V 5 . X , \ n R U G G E D C O M R S G 2300 P N C V 5 . X , \ n R U G G E D C O M R S G 2488 V 4 . X , \ n R U G G E D C O M R S G 2488 V 5 . X , \ n R U G G E D C O M R S G 2488 F , \ n R U G G E D C O M R S G 2488 N C V 4 . X , \ n R U G G E D C O M R S G 2488 N C V 5 . X , \ n R U G G E D C O M R S G 2488 N C V 5 . X , \ n R U G G E D C O M R S G 907 R , \ n R U G G E D C O M R S G 908 C , \ n R U G G E D C O M R S G 909 R , \ n R U G G E D C O M R S G 910 C , \ n R U G G E D C O M R S G 920 P V 4 . X , \ n R U G G E D C O M R S G 920 P V 5 . X , \ n R U G G E D C O M R S G 920 P N C V 4 . X , \ n R U G G E D C O M R S G 920 P N C V 5 . X , \ n R U G G E D C O M R S G 920 P N C V 5 . X , \ n R U G G E D C O M R S L 910 , \ n R U G G E D C O M R S L 910 N C , \ n R U G G E D C O M R S L 910 N C , \ n R U G G E D C O M R S T 2228 , \ n R U G G E D C O M R S T 2228 P , \ n R U G G E D C O M R S T 916 C , \ n R U G G E D C O M R S T 916 P . \ n \ n L o s d i s p o s i t i v o s a f e c t a d o s m a n e j a n i n c o r r e c t a m e n t e s o l i c i t u d e s H T T P p a r c i a l e s , l o q u e l o s h a c e v u l n e r a b l e s a a t a q u e s d e s l o w l o r i s . E s t o p o d r \ u 0 0 e d a p e r m i t i r q u e u n a t a c a n t e r e m o t o c r e e u n a c o n d i c i \ u 0 0 f 3 n d e d e n e g a c i \ u 0 0 f 3 n d e s e r v i c i o q u e p e r s i s t a h a s t a q u e f i n
2023-04-24 12:24:31 +02:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "productcert@siemens.com" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "productcert@siemens.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-400"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:ruggedcom_ros:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.6.0" ,
"matchCriteriaId" : "C6B395AC-2073-41DA-8577-1CF1C71161FB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rmc8388:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC9307A5-118E-4A06-9CC5-931478BE3440"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rs416pv2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D2431F6-1095-4603-8EB2-642D5D859747"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rs416v2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9DD536B4-BA38-4CC5-A480-163FF38FA167"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rs900_\\(32m\\):-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "060D7DB5-AE9D-4AEF-BB26-1AEE5091165A"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rs900g_\\(32m\\):-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D7A756E1-DCD8-4C6D-9467-A354E4AAF842"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg2100_\\(32m\\):-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9D61DD01-FEB7-4714-B621-7405D286DB30"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg2288:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F42A83F2-B151-48E9-BC54-AC81B5C3B017"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg2300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "22A00345-A3E6-40D2-BCB3-9FE042F02119"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg2300p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1B393AE3-6C76-4E36-96D3-90228AA7EC14"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg2488:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7F1DB4EF-5CB1-43BA-AB1F-6D6D48ED859C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg907r:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0CC2D072-D8EA-45A2-9C2D-7AAA65FA683F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg908c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "49083023-8702-491B-A7C3-AF60FB605E9F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg909r:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8FDC0411-3A25-44D1-8929-FF2F4F432F8E"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg910c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "11AA599E-B0FD-4708-A2CB-5B3CA89FD865"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsg920p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1243655B-8636-43CF-8052-ABB5263B0BED"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rsl910:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F0C8879-659D-4A28-BA72-7BE05B5215CC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rst2228:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CDDB741-B3B9-42C2-9C01-A6FC87A26B44"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rst2228p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AAF8B55-5B3E-49EF-B7B4-BCCE11A09858"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rst916c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52713BFF-C34C-4233-AE92-B91D94911802"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rst916p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "24F7373B-E91D-4524-9F1A-0BF4AAC9F461"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-459643.pdf" ,
"source" : "productcert@siemens.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-787941.pdf" ,
"source" : "productcert@siemens.com"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-459643.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-787941.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}