First published: Tue Dec 26 2017(Updated: )
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.1 (excluding)). After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to writeto the device under certain conditions, potentially allowing users located in the adjacentnetwork of the targeted device to perform unauthorized administrative actions.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Scalance Xb-200 Firmware | >=3.0 | |
Siemens SCALANCE XB-200 | ||
Siemens Scalance Xc-200 Firmware | >=3.0 | |
Siemens SCALANCE XC-200 | ||
Siemens Scalance Xp-200 Firmware | >=3.0 | |
Siemens SCALANCE XP-200 | ||
Siemens Scalance Xr300-wg Firmware | >=3.0 | |
Siemens Scalance Xr300-wg | ||
Siemens Scalance Xr-500 Firmware | >=6.1 | |
Siemens Scalance Xr-500 | ||
Siemens Scalance Xm-400 Firmware | >=6.1 | |
Siemens Scalance Xm-400 | ||
Siemens Ruggedcom Ros | <5.0.1 | |
Siemens Ruggedcom Rsl910 | ||
Siemens Ruggedcom Ros | <4.3.4 | |
Siemens Ruggedcom |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-12736.
RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.2 (excluding)).
The severity of CVE-2017-12736 is high with a severity score of 8.8.
The Common Weakness Enumeration (CWE) ID for CVE-2017-12736 is CWE-665 and CWE-20.
You can find more information about CVE-2017-12736 at the following references: [http://www.securityfocus.com/bid/101041](http://www.securityfocus.com/bid/101041), [http://www.securitytracker.com/id/1039463](http://www.securitytracker.com/id/1039463), [http://www.securitytracker.com/id/1039464](http://www.securitytracker.com/id/1039464).