CVE-2017-12736
Summary
| CVE | CVE-2017-12736 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-26 04:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.1 (excluding)). After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to writeto the device under certain conditions, potentially allowing users located in the adjacentnetwork of the targeted device to perform unauthorized administrative actions. |
Risk And Classification
Problem Types: CWE-665
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Ruggedcom | - | All | All | All |
| Hardware | Siemens | Ruggedcom | - | All | All | All |
| Operating System | Siemens | Ruggedcom Ros | All | All | All | All |
| Operating System | Siemens | Ruggedcom Ros | All | All | All | All |
| Hardware | Siemens | Ruggedcom Rsl910 | - | All | All | All |
| Hardware | Siemens | Ruggedcom Rsl910 | - | All | All | All |
| Hardware | Siemens | Scalance Xb-200 | - | All | All | All |
| Hardware | Siemens | Scalance Xb-200 | - | All | All | All |
| Operating System | Siemens | Scalance Xb-200 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xb-200 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xc-200 | - | All | All | All |
| Hardware | Siemens | Scalance Xc-200 | - | All | All | All |
| Operating System | Siemens | Scalance Xc-200 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xc-200 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm-400 | - | All | All | All |
| Hardware | Siemens | Scalance Xm-400 | - | All | All | All |
| Operating System | Siemens | Scalance Xm-400 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xm-400 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xp-200 | - | All | All | All |
| Hardware | Siemens | Scalance Xp-200 | - | All | All | All |
| Operating System | Siemens | Scalance Xp-200 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xp-200 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr-500 | - | All | All | All |
| Hardware | Siemens | Scalance Xr-500 | - | All | All | All |
| Operating System | Siemens | Scalance Xr-500 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr-500 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr300-wg | - | All | All | All |
| Hardware | Siemens | Scalance Xr300-wg | - | All | All | All |
| Operating System | Siemens | Scalance Xr300-wg Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr300-wg Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens | CONFIRM | www.siemens.com | Issue Tracking, Mitigation, Vendor Advisory |
| Siemens Rugged Operating System (ROS) RCDP Access Control Flaw Lets Remote Users Access the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Siemens Scalance RCDP Access Control Flaw Lets Remote Users Access the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591401 Siemens Ruggedcom ROS, SCALANCE Improper Access Control Multiple Vulnerabilities (ICSA-17-271-01B, SSA-856721)