CNNVD-202512-1519 Information

CNNVD ID

CNNVD-202512-1519

CVE-2025-40935

  • CNNVD Published: 2025-12-09

Description (Chinese)

Siemens RUGGEDCOM是德国西门子(Siemens)公司的一个通信设备。为电力,交通,石油和天然气及其他行业提供快速可靠的通信。 Siemens RUGGEDCOM存在输入验证错误漏洞,该漏洞源于TLS证书上传过程中输入验证不足,可能导致设备崩溃和重启。

Description (English)

Siemens RUGGEDCOM is a communications equipment of Siemens, Germany. Rapid and reliable communications for electricity, transport, oil and gas and other industries. Siemens RUGGEDCOM has an input authentication error that stems from the lack of input authentication during the uploading of TLS certificates, which could lead to the collapse and restart of the equipment.

Hazard Level

High

Vulnerability Type

输入验证错误

Affected Vendor

西门子

Published

2025-12-09

Last Modified

2026-02-24

References

https://cert-portal.siemens.com/productcert/html/ssa-763474.html https://vigilance.fr/vulnerability/Siemens-RUGGEDCOM-ROS-V5-X-denial-of-service-via-TLS-Certificate-Upload-Process-49028

Patch

https://cert-portal.siemens.com/productcert/html/ssa-763474.html

Share on: