HIGH✓ PATCH🇬🇧 English

CVE-2015-1448

CVSS 10.0v2.0pub. 2015-02-02upd. 2026-05-06

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

oryginał EN
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Siemens Ruggedcom Firmware

    OS
    Siemens
    ≤ bs4.4.4621.31≤ ss4.4.4624.34
  • Siemens Ruggedcom Win5100

    HW
    Siemens
    wszystkie wersje
  • Siemens Ruggedcom Win5200

    HW
    Siemens
    wszystkie wersje
  • Siemens Ruggedcom Win7000

    HW
    Siemens
    wszystkie wersje
  • Siemens Ruggedcom Win7200

    HW
    Siemens
    wszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2019-12262CRITICAL9.8PL ✓ten sam produkt

Wind River VxWorks — błąd logiczny w kliencie RARP (nieproszone odpowiedzi)

CVE-2019-12255CRITICAL9.8PL ✓ten sam produkt

Buffer Overflow w stosie TCP VxWorks — integer underflow przez TCP Urgent Pointer

CVE-2019-12256CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w parsowaniu opcji IPv4 w Wind River VxWorks

CVE-2019-12260CRITICAL9.8PL ✓ten sam produkt

Buffer Overflow w stosie TCP systemu VxWorks — mylący Urgent Pointer przez opcję TCP AO

CVE-2019-12261CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w TCP stack VxWorks — błąd stanu Urgent Pointer