5.8

CVE-2017-12736

After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions.

This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Scalance Xb-200 Firmware Version >= 3.0
   Siemens ≫ Scalance Xb-200 Version -
Siemens ≫ Scalance Xc-200 Firmware Version >= 3.0
   Siemens ≫ Scalance Xc-200 Version -
Siemens ≫ Scalance Xp-200 Firmware Version >= 3.0
   Siemens ≫ Scalance Xp-200 Version -
Siemens ≫ Scalance Xr300-wg Firmware Version >= 3.0
   Siemens ≫ Scalance Xr300-wg Version -
Siemens ≫ Scalance Xr-500 Firmware Version >= 6.1
   Siemens ≫ Scalance Xr-500 Version -
Siemens ≫ Scalance Xm-400 Firmware Version >= 6.1
   Siemens ≫ Scalance Xm-400 Version -
Siemens ≫ Ruggedcom Ros Version < 5.0.1
   Siemens ≫ Ruggedcom Rsl910 Version -
Siemens ≫ Ruggedcom Ros Version < 4.3.4
   Siemens ≫ Ruggedcom Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.582
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
Siemens 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.8 2.8 5.9
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

http://www.securityfocus.com/bid/101041
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039463
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039464
Third Party Advisory
VDB Entry
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-856721.pdf
Vendor Advisory
Issue Tracking
Mitigation
https://cert-portal.siemens.com/productcert/html/ssa-856721.html