← Vulnerability feed

Vulnerability record · CVE-2012-1803 · published 28 April 2012

CVE-2012-1803: RuggedCom ROS Factory Account Password Derived from MAC Address

Siemens · Ruggedcom Rugged Operating System

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the device banner. Anyone who can read that banner can compute the password and log in remotely, giving unauthenticated-by-design access to mission-critical industrial network gear.

8.5 CVSS 2.0 High EPSS 49% · top 1.2% CWE-310 · CWE-310
8.5CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityFull administrative compromise of mission-critical industrial devices with public exploit code and very high EPSS, though not currently in KEV.

What it is

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the device banner. Anyone who can read that banner can compute the password and log in remotely, giving unauthenticated-by-design access to mission-critical industrial network gear.

Impact

An attacker gains full administrative access to the device over TELNET, remote shell, or serial console, with complete loss of confidentiality, integrity, and availability per the CVSS vector. This allows reconfiguration, traffic interception, and disruption of the managed industrial network.

Attack surface

Reachable over the network via TELNET or rsh, or locally via serial console; the MAC address needed for the password calculation is exposed in the device banner. No prior authentication is required, though the CVSS vector notes medium access complexity and single authentication (the derived credential itself).

Exploitation

Public exploit code exists (Exploit-DB 18779 and a Full Disclosure post), and EPSS is 0.49 (98.8th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV and no ransomware groups are documented using it.

What to do

  • Upgrade RuggedCom ROS to a version later than 3.10.x per the vendor advisory; if no fixed release is available, isolate affected devices.
  • Change or disable the factory account and set unique, strong credentials on every device.
  • Restrict management access (TELNET, rsh, serial) to a dedicated out-of-band or tightly firewalled management network.
  • Disable TELNET and rsh in favor of SSH where supported, and block the banner from being exposed to untrusted networks.
  • Monitor vendor and ICS-CERT advisories for updated firmware and interim guidance.

Detection

  • Alert on TELNET or rsh logins to RuggedCom devices, especially from unexpected source addresses.
  • Audit device configuration for the presence of the default factory account and for unchanged derived passwords.
  • Monitor for banner-grabbing or scanning activity against RuggedCom management ports.
  • Correlate authentication logs across industrial devices for logins using the factory account name.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2012-04/0186.html Broken Link
http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-syste Third Party Advisory
http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A Third Party AdvisoryUS Government Resource
http://seclists.org/fulldisclosure/2012/Apr/277 ExploitMailing ListThird Party Advisory
http://www.exploit-db.com/exploits/18779 ExploitThird Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/889195 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/MAPG-8RCPEN Third Party AdvisoryUS Government Resource
http://www.ruggedcom.com/productbulletin/ros-security-page/ Broken LinkVendor Advisory
http://www.securityfocus.com/bid/53215 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf Broken LinkThird Party AdvisoryUS Government Resource
http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/ Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/75120 Third Party AdvisoryVDB Entry
http://archives.neohapsis.com/archives/bugtraq/2012-04/0186.html Broken Link
http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-syste Third Party Advisory
http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A Third Party AdvisoryUS Government Resource
http://seclists.org/fulldisclosure/2012/Apr/277 ExploitMailing ListThird Party Advisory
http://www.exploit-db.com/exploits/18779 ExploitThird Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/889195 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/MAPG-8RCPEN Third Party AdvisoryUS Government Resource
http://www.ruggedcom.com/productbulletin/ros-security-page/ Broken LinkVendor Advisory
http://www.securityfocus.com/bid/53215 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf Broken LinkThird Party AdvisoryUS Government Resource
http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/ Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/75120 Third Party AdvisoryVDB Entry

Track CVE-2012-1803 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2012-2441Siemens ruggedcom rugged operating system weak password requirements vulnerabilityRuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes …EPSS 8.5%8.3CVE-2013-6925Siemens ruggedcom rugged operating system vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.EPSS 1.9%8.0CVE-2013-6926Siemens ruggedcom rugged operating system incorrect authorization vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ…EPSS 1.5%7.8CVE-2014-1966Siemens ruggedcom rugged operating system vulnerabilityThe SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote atta…EPSS 2.2%5.0CVE-2014-2590Siemens ruggedcom rugged operating system missing authentication for critical function vulnerabilityThe web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…EPSS 2.4%4.3CVE-2015-6675Siemens ruggedcom rugged operating system improper access control vulnerabilitySiemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation pro…EPSS 0.81%4.3CVE-2015-5537Siemens ruggedcom rox ii firmware cleartext storage of sensitive data vulnerabilityThe SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier fo…EPSS 1.1%3.3CVE-2015-7836Siemens ruggedcom rugged operating system information exposure vulnerabilitySiemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding s…EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2012-1803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.