Weak Cipher Configuration in RUGGEDCOM Devices by Siemens
CVE-2021-37209
6.7MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 8 March 2022
What is CVE-2021-37209?
A significant vulnerability exists in various RUGGEDCOM devices due to the default configuration of the SSH server, which permits weak ciphers. This configuration can expose the systems to man-in-the-middle attacks, allowing unauthorized users to intercept, read, or modify data transmitted between legitimate clients and the vulnerable devices. Users are urged to upgrade to the latest software versions to mitigate these security risks.
Affected Version(s)
RUGGEDCOM i800 All versions < V4.3.8
RUGGEDCOM i801 All versions < V4.3.8
RUGGEDCOM i802 All versions < V4.3.8