SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1803

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address…

HIGH 8.5EPSS 49.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 49.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.

CVSS 2.0
8.5 HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
EPSS
49.01% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
siemens/ruggedcom rugged operating system
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.