// For flags

CVE-2012-4698

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

Siemens Ruggedcom Rugged Operating System (ROS) antes de v3.12, ROX I OS hasta v1.14.5, ROX II OS hasta v2.3.0 y RuggedMax OS hasta v4.2.1.4621.22 usa claves privadas para comunicaciones SSL y SSH escritas en código, lo que hace que sea más fácil para atacantes man-in-the-middle el crear servidores falsos y descifrar el tráfico de red aprovechándose de la disponibilidad de estas claves dentro de los archivos de ROS en todas las instalaciones de los clientes.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-08-28 CVE Reserved
  • 2012-12-23 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Ros
Search vendor "Siemens" for product "Ros"
<= 3.11.0
Search vendor "Siemens" for product "Ros" and version " <= 3.11.0"
-
Affected
Siemens
Search vendor "Siemens"
Rox I Os
Search vendor "Siemens" for product "Rox I Os"
<= 1.14.5
Search vendor "Siemens" for product "Rox I Os" and version " <= 1.14.5"
-
Affected
Siemens
Search vendor "Siemens"
Rox Ii Os
Search vendor "Siemens" for product "Rox Ii Os"
<= 2.3.0
Search vendor "Siemens" for product "Rox Ii Os" and version " <= 2.3.0"
-
Affected
Siemens
Search vendor "Siemens"
Ruggedmax Os
Search vendor "Siemens" for product "Ruggedmax Os"
<= 4.2.1.4621.22
Search vendor "Siemens" for product "Ruggedmax Os" and version " <= 4.2.1.4621.22"
-
Affected