SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-12736

This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.

HIGH 8.8EPSS 1.00%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-1188, CWE-665
Affected
siemens/scalance xb-200 firmware · siemens/scalance xc-200 firmware · siemens/scalance xp-200 firmware · siemens/scalance xr300-wg firmware · siemens/scalance xr-500 firmware · siemens/scalance xm-400 firmware · siemens/ruggedcom ros
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.