ZeroHour

CVE-2017-12736

CVSS 3.1
8.8 high
EPSS
<1%p61
Published
()
Modified
Description

After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.

Vendors
siemens
Products
scalance xb-200 firmware, scalance xc-200 firmware, scalance xp-200 firmware, scalance xr300-wg firmware, scalance xr-500 firmware, scalance xm-400 firmware, ruggedcom ros
Weakness
CWE-1188, CWE-665
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news