March 14, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

RUGGEDCOM ROS-based V4 devices are vulnerable to a denial of service attack (Slowloris). By sending partial HTTP requests nonstop, with none completed, the affected web servers will be waiting for the completion of each request, occupying all available HTTP connections. The web server recovers by itself once the attack ends.


Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.

attack connections denial of service denial of service attack devices http http requests partial request requests ros ruggedcom server servers service slowloris ssa the web update vulnerability vulnerable web web server web servers

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Systems Security Officer (ISSO), Junior

@ Dark Wolf Solutions | Remote / Dark Wolf Locations

Cloud Security Engineer

@ ManTech | REMT - Remote Worker Location

SAP Security & GRC Consultant

@ NTT DATA | HYDERABAD, TG, IN

Security Engineer 2 - Adversary Simulation Operations

@ Datadog | New York City, USA