CVE-2013-6926
high
CVSS v3
—
CVSS v2
8.0
VIR risk
8.0
Description
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-324789.pdf
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-340-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-324789.pdf
- http://ics-cert.us-cert.gov/advisories/ICSA-13-340-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-324789.pdf
CWEs
CWE-863
Verify integrity in audit chain (admin only). AS-IS.