VulnerabilityModified
CVE-2015-7836
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.
LOW 3.3EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.
- CVSS 2.0
- 3.3 LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- siemens/ruggedcom rugged operating system
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1033973
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-921524.pdfVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-300-01Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1033973
- http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-921524.pdfVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-300-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.