CVE-2017-2686 describes a vulnerability in all versions of Siemens RUGGEDCOM ROX I devices, allowing an authenticated user to read arbitrary files and access sensitive information via the web interface on port 10000/TCP. This medium-severity flaw (CVSS 6.5) has a low attack complexity and requires authentication, but successful exploitation leads to high confidentiality impact without affecting integrity or availability. While there is no known exploit code in common frameworks like Metasploit or Nuclei, and it's not on the KEV catalog, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.9.0CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_rox_i:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.