Siemens RUGGEDCOM Products Insecure Cryptographic Algorithms Vulnerability Allowing Man-in-the-Middle Attacks

Vulnerability

A vulnerability exists in multiple Siemens RUGGEDCOM products, all versions, due to the support of insecure cryptographic algorithms. This flaw could enable an attacker to conduct a man-in-the-middle attack or impersonate communicating parties.

Impact

Exploitation of this vulnerability could lead to a man-in-the-middle attack, allowing interception and possibly alteration of communications between parties.

Remediation

For RUGGEDCOM ROS V5.X family, users are advised to update to version 5.10.0 or later. For RUGGEDCOM ROS V4.X family, no fix is currently available. General security recommendations include deactivating unnecessary services and restricting access to certain ports from untrusted IP addresses.

Added: Jul 8, 2025, 12:23 PM
Updated: Jul 8, 2025, 12:23 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.3
exploitability
6.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.