Back to search
CVE-2017-2688
Published: Mar 29, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.
| Vendor | Product | Versions |
|---|---|---|
n/a | RUGGEDCOM ROX I All versions | affected RUGGEDCOM ROX I All versions |
Weaknesses (CWE)
References
97170
vdb-entry
x_refsource_BID
1038160
vdb-entry
x_refsource_SECTRACK
https://ics-cert.us-cert.gov/advisories/ICSA-17-087-01
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now