CVE-2017-12736
26.12.2017, 04:29
After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | scalance_xb-200_firmware | 3.0 ≤ |
siemens | scalance_xc-200_firmware | 3.0 ≤ |
siemens | scalance_xp-200_firmware | 3.0 ≤ |
siemens | scalance_xr300-wg_firmware | 3.0 ≤ |
siemens | scalance_xr-500_firmware | 6.1 ≤ |
siemens | scalance_xm-400_firmware | 6.1 ≤ |
siemens | ruggedcom_ros | 𝑥 < 5.0.1 |
siemens | ruggedcom_ros | 𝑥 < 4.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1188 - Insecure Default Initialization of ResourceThe software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
- CWE-665 - Improper InitializationThe software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
References