CVE-2024-56839
published 2025-12-09CVE-2024-56839: A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400…
PriorityP351high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.60%
44.4th percentile
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions < V2.17.0), RUGGEDCOM ROX RX1511 (All versions < V2.17.0), RUGGEDCOM ROX RX1512 (All versions < V2.17.0), RUGGEDCOM ROX RX1524 (All versions < V2.17.0), RUGGEDCOM ROX RX1536 (All versions < V2.17.0), RUGGEDCOM ROX RX5000 (All versions < V2.17.0). Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | ruggedcom_rox_ii_firmware | < 2.17.0 | 2.17.0 |
| siemens | ruggedcom_rox_mx5000 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_mx5000re | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1400 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1500 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1501 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1510 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1511 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1512 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1524 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx1536 | < V2.17.0 | V2.17.0 |
| siemens | ruggedcom_rox_rx5000 | < V2.17.0 | V2.17.0 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX II
cisa_ics·2025-12-09·CVSS 8.8
[HIGH] Siemens RUGGEDCOM ROX II
ICS Advisory
##
Siemens RUGGEDCOM ROX II
Release DateDecember 09, 2025
Alert CodeICSA-26-015-11
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Devices based on RUGGEDCOM ROX before V2.17 contain multiple high severity vulnerabilities. Siemens has released a new version for RUGGEDCOM ROX II family and recommends to update to the latest version.
The following versions of Siemens RUGGEDCOM ROX II are affected:
- RUGGEDCOM ROX II family (CVE-2024-56835, CVE-2024-56836, CVE-2024-56837, CVE-2024-56838, CVE-2024-56839, CVE-2024-56840)
CVSS
Vendor
Equipment
Vulnerabilities
| v3 8.8
| Siemens
| Siemens RUGGEDCOM ROX II
| Improper Neutralization of Special Elements in Output Used by a Downstream Component
GHSA
GHSA-4xh8-gf5r-5x5p: A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2
ghsa_unreviewed·2025-12-09
CVE-2024-56839 [HIGH] CWE-74 GHSA-4xh8-gf5r-5x5p: A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2
A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-09
Published