← Vulnerability feed

Vulnerability record · CVE-2012-2441 · published 28 April 2012

CVE-2012-2441: Siemens ruggedcom rugged operating system weak password requirements vulnerability

Siemens · Ruggedcom Rugged Operating System

RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.

8.5 CVSS 2.0 High EPSS 8.5% · top 5.1% CWE-521 · Weak password requirements
8.5CVSS 2.0 base score
8.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2012-1803RuggedCom ROS Factory Account Password Derived from MAC AddressRuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the d…EPSS 49%analysed8.3CVE-2013-6925Siemens ruggedcom rugged operating system vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.EPSS 1.9%8.0CVE-2013-6926Siemens ruggedcom rugged operating system incorrect authorization vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ…EPSS 1.5%7.8CVE-2014-1966Siemens ruggedcom rugged operating system vulnerabilityThe SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote atta…EPSS 2.2%5.0CVE-2014-2590Siemens ruggedcom rugged operating system missing authentication for critical function vulnerabilityThe web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…EPSS 2.4%4.3CVE-2015-6675Siemens ruggedcom rugged operating system improper access control vulnerabilitySiemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation pro…EPSS 0.81%4.3CVE-2015-5537Siemens ruggedcom rox ii firmware cleartext storage of sensitive data vulnerabilityThe SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier fo…EPSS 1.1%3.3CVE-2015-7836Siemens ruggedcom rugged operating system information exposure vulnerabilitySiemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding s…EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2012-2441), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.