5.8
CVSSv2

CVE-2017-12736

Published: 26/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.1 (excluding)). After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to writeto the device under certain conditions, potentially allowing users located in the adjacentnetwork of the targeted device to perform unauthorized administrative actions.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens scalance_xb-200_firmware

siemens scalance_xc-200_firmware

siemens scalance_xp-200_firmware

siemens scalance_xr300-wg_firmware

siemens scalance_xr-500_firmware

siemens scalance_xm-400_firmware

siemens ruggedcom_ros