Siemens Ruggedcom Rox

Summary

Siemens Ruggedcom Rox devices are affected by an improper access control vulnerability (CVE-2025-40948) that allows authenticated remote attackers to read arbitrary files with root privileges. Siemens has released updated versions for the affected products, and users are advised to update to the latest versions.

IFF Assessment

FOE

This vulnerability allows an attacker to gain root privileges and read sensitive files, posing a significant risk to the integrity and confidentiality of industrial control systems.

Severity

6.8 Medium

The CVSS score of 6.8 indicates a "High" severity vulnerability. This is due to the potential for an authenticated remote attacker to read arbitrary files with root privileges, impacting confidentiality and potentially leading to further system compromise.

Defender Context

This vulnerability affects industrial control systems (ICS) in critical manufacturing sectors, highlighting the need for robust patch management and access control for operational technology (OT) environments. Defenders should prioritize updating Siemens Ruggedcom Rox devices and monitor for any signs of unauthorized file access or privilege escalation.

Read Full Story →