Vulnerability Details CVE-2015-5537
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-5537
-
cpe:2.3:o:siemens:ruggedcom_rox_ii_firmware:-
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.10.1
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.11
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.11.0
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.11.4
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.12
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.12.1
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.12.2
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.12.4
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.2.5
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.3.6
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.4.9
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.5.4
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.6.6
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.7.9
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.8.5
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:3.9.3
-
cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:4.0