VulnerabilityModified
CVE-2014-2590
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
MEDIUM 5.0EPSS 2.41%
Does this matter?
Lower severity and a low EPSS score (2.41%). Track it; it rarely justifies an emergency change on its own.
Description
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- siemens/ruggedcom rugged operating system
- Source
- cve@mitre.org
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01Permissions Required, Third Party Advisory, US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-831997.pdfBroken Link, Vendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01Permissions Required, Third Party Advisory, US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-831997.pdfBroken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.