CVE-2012-4698

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/12/2012
Last modified:
11/04/2025

Description

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:ros:*:*:*:*:*:*:*:* 3.11.0 (including)
cpe:2.3:o:siemens:rox_i_os:*:*:*:*:*:*:*:* 1.14.5 (including)
cpe:2.3:o:siemens:rox_ii_os:*:*:*:*:*:*:*:* 2.3.0 (including)
cpe:2.3:o:siemens:ruggedmax_os:*:*:*:*:*:*:*:* 4.2.1.4621.22 (including)