The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CSiemens Ruggedcom Firmware
OSSiemens≤ bs4.4.4621.31≤ ss4.4.4624.34Siemens Ruggedcom Win5100
HWSiemensall versionsSiemens Ruggedcom Win5200
HWSiemensall versionsSiemens Ruggedcom Win7000
HWSiemensall versionsSiemens Ruggedcom Win7200
HWSiemensall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2019-12262CRITICAL9.8PL ✓same product
Wind River VxWorks — błąd logiczny w kliencie RARP (nieproszone odpowiedzi)
CVE-2019-12255CRITICAL9.8PL ✓same product
Buffer Overflow w stosie TCP VxWorks — integer underflow przez TCP Urgent Pointer
CVE-2019-12256CRITICAL9.8PL ✓same product
Buffer overflow w parsowaniu opcji IPv4 w Wind River VxWorks
CVE-2019-12260CRITICAL9.8PL ✓same product
Buffer Overflow w stosie TCP systemu VxWorks — mylący Urgent Pointer przez opcję TCP AO
CVE-2019-12261CRITICAL9.8PL ✓same product
Buffer overflow w TCP stack VxWorks — błąd stanu Urgent Pointer