Vulnerability Description
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Ruggedcom Rugged Operating System | < 3.12.2 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-340-01Third Party AdvisoryUS Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviBroken LinkVendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-13-340-01Third Party AdvisoryUS Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviBroken LinkVendor Advisory
FAQ
What is CVE-2013-6926?
CVE-2013-6926 is a vulnerability with a CVSS score of 8.0 (HIGH). The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2...
How severe is CVE-2013-6926?
CVE-2013-6926 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6926?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Ruggedcom Rugged Operating System.