CVE-2012-2441
Description
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
References
- http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars
- http://seclists.org/fulldisclosure/2012/Apr/277
- http://www.kb.cert.org/vuls/id/889195
- http://www.ruggedcom.com/productbulletin/ros-security-page/
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf
- http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75244
- http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars
- http://seclists.org/fulldisclosure/2012/Apr/277
- http://www.kb.cert.org/vuls/id/889195
- http://www.ruggedcom.com/productbulletin/ros-security-page/
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf
- http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75244
CWEs
CWE-521
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.