← Vulnerability feed

Vulnerability record · CVE-2015-6675 · published 11 September 2015

CVE-2015-6675: Siemens ruggedcom rugged operating system improper access control vulnerability

Siemens · Ruggedcom Rugged Operating System

Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.

4.3 CVSS 2.0 Medium EPSS 0.81% · top 44.7% CWE-284 · Improper access control
4.3CVSS 2.0 base score
0.81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.

AV:A/AC:M/Au:N/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6675 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2012-1803RuggedCom ROS Factory Account Password Derived from MAC AddressRuggedCom Rugged Operating System (ROS) 3.10.x and earlier ships with a factory account whose password is derived from the MAC address shown in the d…EPSS 49%analysed8.5CVE-2012-2441Siemens ruggedcom rugged operating system weak password requirements vulnerabilityRuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes …EPSS 8.5%8.3CVE-2013-6925Siemens ruggedcom rugged operating system vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.EPSS 1.9%8.0CVE-2013-6926Siemens ruggedcom rugged operating system incorrect authorization vulnerabilityThe integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ…EPSS 1.5%7.8CVE-2014-1966Siemens ruggedcom rugged operating system vulnerabilityThe SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote atta…EPSS 2.2%5.0CVE-2014-2590Siemens ruggedcom rugged operating system missing authentication for critical function vulnerabilityThe web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…EPSS 2.4%4.3CVE-2015-5537Siemens ruggedcom rox ii firmware cleartext storage of sensitive data vulnerabilityThe SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier fo…EPSS 1.1%3.3CVE-2015-7836Siemens ruggedcom rugged operating system information exposure vulnerabilitySiemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding s…EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2015-6675), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.