CVE-2012-1803 EXPLOIT
8.5
HIGH · CVSS 2.0 · EPSS 49% (pctl 99)
Patch early
A public exploit exists.
Description
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.
Scoring
| CVSS | 8.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
| EPSS | 49.01% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-04-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| siemens | ruggedcom rugged operating system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RuggedCom Devices - Backdoor Access | 2012-04-24 |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0186.html
- http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars
- http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A
- http://seclists.org/fulldisclosure/2012/Apr/277
- http://www.exploit-db.com/exploits/18779
- http://www.kb.cert.org/vuls/id/889195
- http://www.kb.cert.org/vuls/id/MAPG-8RCPEN
- http://www.ruggedcom.com/productbulletin/ros-security-page/
- http://www.securityfocus.com/bid/53215
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf
- http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75120
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0186.html
- http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars
- http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A
- http://seclists.org/fulldisclosure/2012/Apr/277
- http://www.exploit-db.com/exploits/18779
- http://www.kb.cert.org/vuls/id/889195
- http://www.kb.cert.org/vuls/id/MAPG-8RCPEN
- http://www.ruggedcom.com/productbulletin/ros-security-page/
→ the Explorer · watch your stack · NVD