The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- Summary
- The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity stops.
- Remediation
- Create a firewall rule that blocks the UDP ports if not required. The device uses UDP 34964 and one port in range 49152-65535 for discovery protocols like LLDP, DCP, MRP etc.
