PatchSiren cyber security CVE debrief
CVE-2024-56835 Siemens CVE debrief
CVE-2024-56835 is a high-severity code-injection vulnerability in the DHCP Server configuration file of Siemens RUGGEDCOM ROX II family products. According to the advisory, an attacker could leverage the flaw to spawn a reverse shell and gain root access on the affected system. Siemens and CISA list a vendor fix: update to V2.17.0 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX II family
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2025-12-09
- Advisory published
- 2025-12-09
- Advisory updated
- 2025-12-09
Who should care
OT/ICS operators using Siemens RUGGEDCOM ROX II family devices, plant and infrastructure defenders, and teams responsible for asset management, patching, and network segmentation in industrial environments.
Technical summary
The advisory describes code injection in the DHCP Server configuration file on affected Siemens RUGGEDCOM ROX II family products. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, scoring 8.8 (High), indicating a network-reachable issue that requires low privileges and can have full confidentiality, integrity, and availability impact. The stated consequence is reverse-shell execution leading to root access.
Defensive priority
High
Recommended defensive actions
- Update affected Siemens RUGGEDCOM ROX II family devices to V2.17.0 or later.
- Review whether any affected devices are reachable from untrusted networks and tighten segmentation and access controls.
- Monitor affected systems for unexpected changes to DHCP configuration files or other signs of tampering.
- Validate device integrity and configuration after patching, especially in operational environments where availability is critical.
- Follow CISA ICS recommended practices and Siemens vendor guidance for deployment, testing, and recovery planning.
Evidence notes
All core claims come from the supplied CISA CSAF advisory metadata and referenced Siemens advisory materials. The source describes code injection in the DHCP Server configuration file and states an attacker could spawn a reverse shell and gain root access. The supplied metadata also lists a CVSS 3.1 score of 8.8 with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and a remediation to update to V2.17.0 or later. Supplied publishedAt and modifiedAt are both 2025-12-09.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-56835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-56835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-56835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-56835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-11.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-912274.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-912274.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-015-11.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-11
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.