Unrated severityNVD Advisory· Published Aug 3, 2015· Updated May 6, 2026
CVE-2015-5537
CVE-2015-5537
Description
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-396873.pdfnvdBroken LinkPatchVendor Advisory
- www.securitytracker.com/id/1033022nvdBroken LinkThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-15-202-03AnvdBroken LinkThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.