CVE-2023-52238: Siemens Ruggedcom RST2228
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web server of the affected systems leaks the MACSEC key in clear text to a logged in user. An attacker with the credentials of a low privileged user could retrieve the MACSEC key and access (decrypt) the ethernet frames sent by authorized recipients.
Affected products
- Siemens Ruggedcom RST2228: before V5.9.0 (fixed in V5.9.0)
- Siemens Ruggedcom RST2228P: before V5.9.0 (fixed in V5.9.0)
Published 2024-07-09. Last modified 2026-06-17.