The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM RMC8388 V4.X
- RUGGEDCOM RMC8388 V5.X
- RUGGEDCOM RMC8388NC V4.X
- RUGGEDCOM RMC8388NC V5.X
- RUGGEDCOM RSG2488 V4.X
- RUGGEDCOM RSG2488 V5.X
- RUGGEDCOM RSG2488NC V4.X
- RUGGEDCOM RSG2488NC V5.X
- RUGGEDCOM RSG907R
- RUGGEDCOM RSG908C
- RUGGEDCOM RSG909R
- RUGGEDCOM RSG910C
- Summary
- The embedded DENX U-Boot boot loader has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled. The security vulnerability could be exploited by an attacker with local access to the affected systems. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
- Remediation
- Disable boot interface access during boot up via the 'bootoption.txt' file parameter 'Security = yes' to mitigate CVE-2018-18440.
