CVE-2017-12736

After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:scalance_xr300-wg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr300-wg:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:scalance_xr-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr-500:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_ros:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rsl910:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_ros:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-12-26 04:29

Updated : 2025-08-12 12:15


NVD link : CVE-2017-12736

Mitre link : CVE-2017-12736

CVE.ORG link : CVE-2017-12736


JSON object : View

Products Affected

siemens

  • scalance_xb-200
  • scalance_xm-400_firmware
  • scalance_xr-500_firmware
  • ruggedcom
  • scalance_xp-200
  • scalance_xc-200_firmware
  • ruggedcom_rsl910
  • scalance_xm-400
  • scalance_xp-200_firmware
  • ruggedcom_ros
  • scalance_xb-200_firmware
  • scalance_xc-200
  • scalance_xr300-wg
  • scalance_xr-500
  • scalance_xr300-wg_firmware
CWE
CWE-1188

Initialization of a Resource with an Insecure Default

CWE-665

Improper Initialization