CVE-2024-41797: Siemens Ruggedcom RST2428P

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.1), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.1), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.1), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.1), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.1), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.1), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.1), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.1), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.1), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.1), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.1), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.1), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.1), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.1), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.1), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.1), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.1), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.1), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.1), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.1), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.1). Affected devices contain an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to invoke an internal "do system" command which exceeds their privileges. This command allows the execution of certain low-risk actions, the most critical of which is clearing the local system log.

Affected products

  • Siemens Ruggedcom RST2428P: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC316-8: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC324-4: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC324-4 Eec: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC332: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC416-8: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC424-4: before V3.1 (fixed in V3.1)
  • Siemens Scalance XC432: before V3.1 (fixed in V3.1)
  • Siemens Scalance XCH328: before V3.1 (fixed in V3.1)
  • Siemens Scalance XCM324: before V3.1 (fixed in V3.1)
  • Siemens Scalance XCM328: before V3.1 (fixed in V3.1)
  • Siemens Scalance XCM332: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR302-32: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR322-12: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR326-8: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR326-8 Eec: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR502-32: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR522-12: before V3.1 (fixed in V3.1)
  • Siemens Scalance XR526-8: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRH334 24 V Dc, 8xfo, Cc: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRM334 230 V Ac, 12xfo: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRM334 230 V Ac, 8xfo: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRM334 230v Ac, 2x10g, 24xsfp, 8xsfp+: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRM334 24 V Dc, 12xfo: before V3.1 (fixed in V3.1)
  • Siemens Scalance XRM334 24 V Dc, 8xfo: before V3.1 (fixed in V3.1)
  • and 4 more

Published 2025-06-10. Last modified 2026-06-17.