First published: Tue Dec 17 2013(Updated: )
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens RuggedCom Rugged Operating System | <3.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6926 allows remote authenticated users to bypass restrictions on administrative actions, potentially leading to unauthorized control over the device.
CVE-2013-6926 affects all versions of Siemens RuggedCom ROS prior to 3.12.2.
CVE-2013-6926 can be exploited by users with guest or operator account privileges.
Organizations can mitigate the risks associated with CVE-2013-6926 by upgrading to Siemens RuggedCom ROS version 3.12.2 or later.
CVE-2013-6926 is considered a significant vulnerability due to its potential for unauthorized administrative access.