First published: Wed Mar 29 2017(Updated: )
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens ROX I OS | <=2.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2686 is classified as a critical vulnerability due to the potential for unauthorized access to sensitive information.
To fix CVE-2017-2686, update the Siemens RUGGEDCOM ROX I to a version newer than 2.9.0.
Any user operating Siemens RUGGEDCOM ROX I versions up to 2.9.0 is affected by CVE-2017-2686.
CVE-2017-2686 allows an authenticated user to read arbitrary files, which may include sensitive information stored on the device.
Yes, an attacker must be an authenticated user in order to exploit CVE-2017-2686 and access the vulnerable web interface.