The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM RMC8388 V5.X
- RUGGEDCOM RS416Pv2 V5.X
- RUGGEDCOM RS416v2 V5.X
- RUGGEDCOM RS900 (32M) V5.X
- RUGGEDCOM RS900G (32M) V5.X
- RUGGEDCOM RSG2100 (32M) V5.X
- RUGGEDCOM RSG2100P (32M) V5.X
- RUGGEDCOM RSG2288 V5.X
- RUGGEDCOM RSG2300 V5.X
- RUGGEDCOM RSG2300P V5.X
- RUGGEDCOM RSG2488 V5.X
- RUGGEDCOM RSG907R
- Summary
- Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.
- Remediation
- Update to V5.10.1 or later version
