ICS-CERT warns of SSL security flaw in RuggedCom industrial networking devices

22.08.2012

Back in April, Clarke after notifying the vendor of the problem in February through US-CERT.

That vulnerability consisted of a hard-coded "factory" account that provided backdoor access to RuggedCom devices running ROS. The company addressed the issue by releasing firmware updates in May and June.

If this new vulnerability is confirmed, it wouldn't be the first time a networking equipment manufacturer hard-codes private keys directly into its devices.

Back in June, a security researcher revealed that multiple devices from F5 Networks that allowed unauthorized users to gain administrative access to them.

That incident at the Black Hat USA 2012 security conference in July.