CVE-2017-12736
8.8
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD (Secondary)
Description
After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions.
This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xb 200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xc 200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xp 200 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr300 Wg | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr 500 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xm 400 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rsl910 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom | All versions |
Related CWEs
CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CWE-665
Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
References (9)
Source: productcert@siemens.com
Third Party AdvisoryVDB Entry
Source: productcert@siemens.com
Third Party AdvisoryVDB Entry
Source: productcert@siemens.com
Source: productcert@siemens.com
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory
Timeline
No history available yet.