Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Flaws Patched in Siemens RUGGEDCOM NMS Product

An update released by Siemens for its RUGGEDCOM network management system (NMS) patches a couple of cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities.

Used in various sectors worldwide, the RUGGEDCOM NMS allows organizations to monitor, configure and maintain their RUGGEDCOM mission-critical networks.

An update released by Siemens for its RUGGEDCOM network management system (NMS) patches a couple of cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities.

Used in various sectors worldwide, the RUGGEDCOM NMS allows organizations to monitor, configure and maintain their RUGGEDCOM mission-critical networks.

According to advisories published by Siemens and ICS-CERT, the product is affected by flaws that may allow a remote attacker to perform administrative operations.

The CSRF vulnerability, tracked as CVE-2017-2682 and assigned a CVSS score of 8.8, affects the product’s web interface and it can be exploited to get an authenticated user to execute various commands on behalf of the attacker. The attacker needs to trick the targeted user into clicking on a specially crafted link.

The XSS flaw, identified as CVE-2017-2683 and assigned a CVSS score of 6.3, could allow a non-privileged attacker to obtain administrative permissions by getting a user to click on a malicious link.

2017 Singapore ICS Cyber Security Conference Call for Papers is Open

Advertisement. Scroll to continue reading.

The vulnerabilities affect all versions of the RUGGEDCOM NMS, for both Windows and Linux, prior to 2.1.0. Siemens has advised customers to update their installations to the latest version and configure their environments as specified in the company’s operational guidelines for industrial security.

ICS-CERT said there was no evidence that the flaws had been exploited for malicious purposes.

In recent months, Siemens has also released security updates for SIPROTEC, SCALANCE, Desigo PX, SIMATIC and various other products.

Related: Learn More at the 2017 Singapore ICS Cyber Security Conference

Related: Recently Patched NTP Flaws Affect Siemens RUGGEDCOM Devices

Related: XSS, SQLi Flaws Found in Network Management Systems

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.