CVE-2023-52238 is a vulnerability affecting RUGGEDCOM RST2228 and RST2228P devices (all versions prior to V5.9.0) where the web server inadvertently exposes the MACSEC key in clear text to authenticated users. This medium-severity vulnerability (CVSS 4.3) allows a low-privileged attacker to retrieve the MACSEC key, potentially enabling them to decrypt Ethernet frames. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | RUGGEDCOM RST2228 | >= 0, < V5.9.0CNA affecteddefault unknown | |
| Siemens | RUGGEDCOM RST2228P | >= 0, < V5.9.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.