CVE-2017-12736: Siemens Ruggedcom Ros

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.

Affected products

  • Siemens Ruggedcom Ros: before 5.0.1 (fixed in 5.0.1); before 4.3.4 (fixed in 4.3.4)
  • Siemens Scalance Xb-200 Firmware: from 3.0
  • Siemens Scalance Xc-200 Firmware: from 3.0
  • Siemens Scalance Xm-400 Firmware: from 6.1
  • Siemens Scalance XP-200 Firmware: from 3.0
  • Siemens Scalance XR-500 Firmware: from 6.1
  • Siemens Scalance XR300-Wg Firmware: from 3.0

Published 2017-12-26. Last modified 2026-06-17.