SSA-170375 PUBLISHED CVSS 7.5 HIGH

The web server of the affected devices allow a low privileged user to access hashes and password salts of all system's users, including admin users. An attacker could use the obtained information to brute force the passwords offline.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensRUGGEDCOM RS900NC
SiemensRUGGEDCOM RS910
SiemensRUGGEDCOM RSG2300NC V4.X
SiemensRUGGEDCOM RS8000NC
SiemensRUGGEDCOM RSG2200
SiemensRUGGEDCOM RS416
SiemensRUGGEDCOM RS910W
SiemensRUGGEDCOM i801
SiemensRUGGEDCOM RS910NC
SiemensRUGGEDCOM i803
SiemensRUGGEDCOM RS416Pv2 V5.X
SiemensRUGGEDCOM M2200
SiemensRUGGEDCOM RS1600FNC
SiemensRUGGEDCOM RMC8388NC V4.X
SiemensRUGGEDCOM RSG2100NC
SiemensRUGGEDCOM RS401
SiemensRUGGEDCOM M2100NC
SiemensRUGGEDCOM RS900MNC-GETS-C01
SiemensRUGGEDCOM RS920W
SiemensRUGGEDCOM RS900GNC

…and 116 more

Timeline

References

Open in Interactive Console →