Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4698

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-4698
Last Modified 20 May 2013 11:20:36
Published 23 Dec 2012 04:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-4698

Summary

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

Vulnerable Systems

Operating System

  • Siemens Ros 3.11.0

  • Siemens Rox I Os 1.14.5

  • Siemens Rox Ii Os 2.3.0

  • Siemens Ruggedmax Os 4.2.1.4621.22


References

CONFIRM - https://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-622607.pdf

MISC - http://www.us-cert.gov/control_systems/pdf/ICSA-12-354-01.pdf

CONFIRM - http://www.ruggedcom.com/productbulletin/ros-security-page/

MISC - http://ics-cert.us-cert.gov/advisories/ICSA-12-354-01A


Last Updated: 27 May 2016 11:01:29