CVE Vulnerabilities

CVE-2015-5537

Cleartext Storage of Sensitive Information

Published: Aug 03, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Ruggedcom_rox_ii_firmware Siemens - (including) - (including)
Ruggedcom_rugged_operating_system Siemens * 4.2.0 (excluding)

Potential Mitigations

References