Description
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
http://ics-cert.us-cert.gov/advisories/ICSA-13-340-01
Broken Link, Vendor Advisory x_refsource_confirm
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-324789.pdf
Scores
EPSS
0.0056
EPSS Percentile
68.5%
Details
CWE
CWE-330
Status
published
Products (1)
siemens/ruggedcom_rugged_operating_system
< 3.12.2
Published
Dec 17, 2013
Tracked Since
Feb 18, 2026