PT-2017-12674 · Siemens · Scalance Xm-400+4
CVE-2017-12736
·
Publicado
2017-12-26
·
Atualizado
2025-08-12
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM ROS for RSL910 devices versions prior to 5.0.1
RUGGEDCOM ROS for all other devices versions prior to 4.3.4
SCALANCE XB-200/XC-200/XP-200/XR300-WG versions 3.0 through 3.0.2 (excluding 3.0.2)
SCALANCE XR-500/XM-400 versions 6.1 through 6.1.1 (excluding 6.1.1)
Description
A vulnerability has been identified that potentially allows users to perform unauthorized administrative actions on affected devices. The Ruggedcom Discovery Protocol (RCDP) can still write to the device under certain conditions after initial configuration, posing a risk to devices on adjacent networks.
Recommendations
For RUGGEDCOM ROS for RSL910 devices versions prior to 5.0.1, update to version 5.0.1 or later.
For RUGGEDCOM ROS for all other devices versions prior to 4.3.4, update to version 4.3.4 or later.
For SCALANCE XB-200/XC-200/XP-200/XR300-WG versions 3.0 through 3.0.2 (excluding 3.0.2), update to version 3.0.2 or later.
For SCALANCE XR-500/XM-400 versions 6.1 through 6.1.1 (excluding 6.1.1), update to version 6.1.1 or later.
As a temporary workaround, consider restricting access to the RCDP to minimize the risk of exploitation.
Correção
Improper Initialization
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ruggedcom Ros
Scalance X-200
Scalance Xm-400
Scalance Xr-500
Scalance Xr-300Wg