The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM RMC8388 V5.X
- RUGGEDCOM RMC8388NC V5.X
- RUGGEDCOM RS416NCv2 V5.X
- RUGGEDCOM RS416PNCv2 V5.X
- RUGGEDCOM RS416Pv2 V5.X
- RUGGEDCOM RS416v2 V5.X
- RUGGEDCOM RS900 (32M) V5.X
- RUGGEDCOM RS900G (32M) V5.X
- RUGGEDCOM RS900GNC(32M) V5.X
- RUGGEDCOM RS900NC(32M) V5.X
- RUGGEDCOM RSG2100 (32M) V5.X
- RUGGEDCOM RSG2100NC(32M) V5.X
- Summary
- The affected products do not properly enforce interface access restrictions when changing from management to non-management interface configurations until a system reboot occurs, despite configuration being saved. This could allow an attacker with network access and credentials to gain access to device through non-management and maintain SSH access to the device until reboot.
- Remediation
- Update to V5.10.0 or later version
