Vulnerability Description
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Ruggedcom Rugged Operating System | < 3.11.0 |
| Siemens | Ruggedcom Rs950G | - |
| Siemens | Ruggedcom Rsg2488 | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01Permissions RequiredThird Party AdvisoryUS Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviBroken LinkVendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01Permissions RequiredThird Party AdvisoryUS Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviBroken LinkVendor Advisory
FAQ
What is CVE-2014-2590?
CVE-2014-2590 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface ...
How severe is CVE-2014-2590?
CVE-2014-2590 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2590?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Ruggedcom Rugged Operating System, Siemens Ruggedcom Rs950G, Siemens Ruggedcom Rsg2488.