CVE-2023-52238 MEDIUM

CVE-2023-52238

Vendor Siemens
Product RUGGEDCOM RST2228
Weakness CWE-200 · Info exposure
Published July 9, 2024
Last update August 27, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

A vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web server of the affected systems leaks the MACSEC key in clear text to a logged in user. An attacker with the credentials of a low privileged user could retrieve the MACSEC key and access (decrypt) the ethernet frames sent by authorized recipients.

Key dates

02Disclosure timeline

July 9, 2024 CVE published
August 27, 2025 Record updated