CVE-2015-5537
03.08.2015, 01:59
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | ruggedcom_rox_ii_firmware | - |
siemens | ruggedcom_rugged_operating_system | 𝑥 < 4.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References