HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2015-1448

CVSS 10.0v2.0pub. 2015-02-02upd. 2026-05-06

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Siemens Ruggedcom Firmware

    OS
    Siemens
    ≤ bs4.4.4621.31≤ ss4.4.4624.34
  • Siemens Ruggedcom Win5100

    HW
    Siemens
    all versions
  • Siemens Ruggedcom Win5200

    HW
    Siemens
    all versions
  • Siemens Ruggedcom Win7000

    HW
    Siemens
    all versions
  • Siemens Ruggedcom Win7200

    HW
    Siemens
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2019-12262CRITICAL9.8PL ✓same product

Wind River VxWorks — błąd logiczny w kliencie RARP (nieproszone odpowiedzi)

CVE-2019-12255CRITICAL9.8PL ✓same product

Buffer Overflow w stosie TCP VxWorks — integer underflow przez TCP Urgent Pointer

CVE-2019-12256CRITICAL9.8PL ✓same product

Buffer overflow w parsowaniu opcji IPv4 w Wind River VxWorks

CVE-2019-12260CRITICAL9.8PL ✓same product

Buffer Overflow w stosie TCP systemu VxWorks — mylący Urgent Pointer przez opcję TCP AO

CVE-2019-12261CRITICAL9.8PL ✓same product

Buffer overflow w TCP stack VxWorks — błąd stanu Urgent Pointer