VDB
CVE-2012-1803
CVE-2012-1803
PUBLISHED
CVSS 8.5 HIGH
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.
EPSS 63.49% · 98.4th percentile
Risk Scores
CVSS 2.0
8.5
EPSS Score
63.49%
98.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| siemens | ruggedcom_rugged_operating_system | 3.2.0 |
Timeline
- Apr 24, 2012 CVE Published
- Apr 24, 2012 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://www.exploit-db.com/exploits/18779 url
- http://www.kb.cert.org/vuls/id/889195 url
- http://www.kb.cert.org/vuls/id/MAPG-8RCPEN url
- http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/ url
- ruggedcom-operating-system-backdoor(75120) vdb
- 20120423 RuggedCom - Backdoor Accounts in my SCADA network? You don't say... mailing-list
- http://www.ruggedcom.com/productbulletin/ros-security-page/ url
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf url
- 20120423 RuggedCom - Backdoor Accounts in my SCADA network? You don't say... mailing-list
- http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A url
- http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars url
- 53215 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2012-1803 advisory
- http://www.ruggedcom.com/productbulletin/ros-security-page url
- http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor url