Unauthorized Access Vulnerability in RUGGEDCOM and SCALANCE Products
CVE-2017-12736

8.8HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
26 December 2017

What is CVE-2017-12736?

A vulnerability exists in RUGGEDCOM and SCALANCE products due to the Ruggedcom Discovery Protocol (RCDP), which can write to devices under certain conditions. This flaw allows users within the adjacent network to potentially execute unauthorized administrative actions on the devices, emphasizing the need for proper security measures and timely updates to safeguard against unauthorized access.

Affected Version(s)

RUGGEDCOM i800 0

RUGGEDCOM i800NC 0

RUGGEDCOM i801 0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-12736 : Unauthorized Access Vulnerability in RUGGEDCOM and SCALANCE Products