Vulnerability record · CVE-2012-1803 · published 28 April 2012
CVE-2012-1803: RuggedCom ROS Factory Account Password Derived from MAC Address
Siemens · Ruggedcom Rugged Operating System
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the device banner. Anyone who can read that banner can compute the password and log in remotely, giving unauthenticated-by-design access to mission-critical industrial network gear.
Description
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.
AV:N/AC:M/Au:S/C:C/I:C/A:C
Automated analysis
high priorityFull administrative compromise of mission-critical industrial devices with public exploit code and very high EPSS, though not currently in KEV.
What it is
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the device banner. Anyone who can read that banner can compute the password and log in remotely, giving unauthenticated-by-design access to mission-critical industrial network gear.
Impact
An attacker gains full administrative access to the device over TELNET, remote shell, or serial console, with complete loss of confidentiality, integrity, and availability per the CVSS vector. This allows reconfiguration, traffic interception, and disruption of the managed industrial network.
Attack surface
Reachable over the network via TELNET or rsh, or locally via serial console; the MAC address needed for the password calculation is exposed in the device banner. No prior authentication is required, though the CVSS vector notes medium access complexity and single authentication (the derived credential itself).
Exploitation
Public exploit code exists (Exploit-DB 18779 and a Full Disclosure post), and EPSS is 0.49 (98.8th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV and no ransomware groups are documented using it.
What to do
- Upgrade RuggedCom ROS to a version later than 3.10.x per the vendor advisory; if no fixed release is available, isolate affected devices.
- Change or disable the factory account and set unique, strong credentials on every device.
- Restrict management access (TELNET, rsh, serial) to a dedicated out-of-band or tightly firewalled management network.
- Disable TELNET and rsh in favor of SSH where supported, and block the banner from being exposed to untrusted networks.
- Monitor vendor and ICS-CERT advisories for updated firmware and interim guidance.
Detection
- Alert on TELNET or rsh logins to RuggedCom devices, especially from unexpected source addresses.
- Audit device configuration for the presence of the default factory account and for unchanged derived passwords.
- Monitor for banner-grabbing or scanning activity against RuggedCom management ports.
- Correlate authentication logs across industrial devices for logins using the factory account name.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1803 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.