CVE-2024-56835

8.8

Siemens · RUGGEDCOM ROX

A code injection vulnerability in the DHCP server configuration of Siemens RUGGEDCOM ROX devices allows authenticated attackers to gain root access via a reverse shell.

Executive summary

A critical code injection vulnerability in Siemens RUGGEDCOM ROX devices allows authenticated attackers to execute arbitrary commands and achieve full system compromise.

Vulnerability

The vulnerability is a code injection flaw (CWE-74) located within the DHCP server configuration file handling process. Authenticated attackers with low privileges can inject malicious elements to spawn a reverse shell, resulting in unauthorized root-level access to the device.

Business impact

The exploitation of this vulnerability poses a severe risk to industrial control environments, as it grants an attacker complete control over the affected networking hardware. With root access, an adversary could facilitate lateral movement, manipulate network traffic, or disrupt critical infrastructure operations. Given the CVSS score of 8.8, this vulnerability is classified as high severity and requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Update all affected RUGGEDCOM ROX devices to firmware version V2.17.0 or later as specified in the Siemens security advisory.

Proactive Monitoring: Review system logs for unauthorized configuration changes, unexpected service restarts, or suspicious outbound network connections originating from the device.

Compensating Controls: Restrict access to the device management interface to trusted administrative networks and implement strict network segmentation to minimize the impact of a potential compromise.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The ability for an attacker to achieve root access via code injection constitutes a significant security failure that threatens the integrity and availability of industrial network infrastructure. Organizations operating these Siemens RUGGEDCOM devices must prioritize the deployment of the V2.17.0 firmware update across all impacted units. Failure to remediate this vulnerability leaves the affected systems exposed to persistent unauthorized access and potential manipulation by malicious actors.

More Siemens CVEs

Sources