CVE-2014-2590
CVE-2014-2590 is a medium-severity vulnerability in Siemens Ruggedcom Rugged Operating System with a CVSS 2.0 base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.0)
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Siemens Ruggedcom Rugged Operating System
- Published:
- Last modified:
Description
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
Frequently asked questions
- What is CVE-2014-2590?
- The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
- How severe is CVE-2014-2590?
- CVE-2014-2590 has a CVSS 2.0 base score of 5.0, rated medium severity.
- Is CVE-2014-2590 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-2590?
- CVE-2014-2590 affects Siemens Ruggedcom Rugged Operating System. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2014-2590?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2014-2590 published?
- CVE-2014-2590 was published on 2014-04-01 and last updated on 2026-06-17.
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-831997.pdf
Affected products (1)
- cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:*:*:*:*:*:*:*:*
More vulnerabilities in Siemens Ruggedcom Rugged Operating System
- CVE-2012-2441 — High (CVSS 8.5): RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address…
- CVE-2012-1803 — High (CVSS 8.5): RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC…
- CVE-2013-6925 — High (CVSS 8.3): The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by…
- CVE-2013-6926 — High (CVSS 8.0): The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended…
- CVE-2014-1966 — High (CVSS 7.8): The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0…
- CVE-2015-6675 — Medium (CVSS 4.3): Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers…
All CVEs affecting Siemens Ruggedcom Rugged Operating System →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-20357 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-58115 — Critical (CVSS 10.0): A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running…
- CVE-2026-63508 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to…
- CVE-2026-56163 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2026-64812 — Critical (CVSS 10.0): In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- CVE-2026-60644 — Critical (CVSS 10.0): Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →