CVE-2014-2590
CVE-2014-2590 is a medium-severity vulnerability in Siemens Ruggedcom Rugged Operating System with a CVSS 2.0 base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.0)
- EPSS exploit prediction: 2% (84th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Siemens Ruggedcom Rugged Operating System
- Published:
- Last modified:
Description
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
Frequently asked questions
- What is CVE-2014-2590?
- The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
- How severe is CVE-2014-2590?
- CVE-2014-2590 has a CVSS 2.0 base score of 5.0, rated medium severity.
- Is CVE-2014-2590 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (84th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-2590?
- CVE-2014-2590 affects Siemens Ruggedcom Rugged Operating System. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2014-2590?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2014-2590 published?
- CVE-2014-2590 was published on 2014-04-01 and last updated on 2026-06-17.
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-087-01
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-831997.pdf
Affected products (1)
- cpe:2.3:o:siemens:ruggedcom_rugged_operating_system:*:*:*:*:*:*:*:*
More vulnerabilities in Siemens Ruggedcom Rugged Operating System
- CVE-2012-2441 — High (CVSS 8.5): RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address…
- CVE-2012-1803 — High (CVSS 8.5): RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC…
- CVE-2013-6925 — High (CVSS 8.3): The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by…
- CVE-2013-6926 — High (CVSS 8.0): The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended…
- CVE-2014-1966 — High (CVSS 7.8): The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0…
- CVE-2015-6675 — Medium (CVSS 4.3): Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers…
All CVEs affecting Siemens Ruggedcom Rugged Operating System →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →