MEDIUM · 4.3

CVE-2012-4698

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communi...

Vulnerability Description

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SiemensRos<= 3.11.0
SiemensRox I Os<= 1.14.5
SiemensRox Ii Os<= 2.3.0
SiemensRuggedmax Os<= 4.2.1.4621.22

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4698?

CVE-2012-4698 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communi...

How severe is CVE-2012-4698?

CVE-2012-4698 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4698?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Ros, Siemens Rox I Os, Siemens Rox Ii Os, Siemens Ruggedmax Os.