PatchSiren cyber security CVE debrief
CVE-2024-56839 Siemens CVE debrief
CVE-2024-56839 affects Siemens RUGGEDCOM ROX II family devices when VRF (Virtual Routing and Forwarding) is in use. According to the supplied advisory text, an attacker could leverage this condition to achieve code injection and execute arbitrary code as root. The CVE was published on 2025-12-09 and is rated HIGH with CVSS 7.2.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX II family
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2025-12-09
- Advisory published
- 2025-12-09
- Advisory updated
- 2025-12-09
Who should care
OT/ICS operators, network administrators, and security teams responsible for Siemens RUGGEDCOM ROX II family deployments, especially systems where VRF is enabled.
Technical summary
The supplied CSAF advisory describes a code injection issue in the Siemens RUGGEDCOM ROX II family that is triggered when the affected device is using VRF. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating network reachability but requiring high privileges. The stated impact is arbitrary code execution as root.
Defensive priority
High. The issue is remotely reachable, can lead to root-level execution, and affects an industrial networking product family. Prioritize devices confirmed to use VRF and move affected systems to the fixed release as soon as operationally feasible.
Recommended defensive actions
- Update affected Siemens RUGGEDCOM ROX II devices to V2.17.0 or later, per the vendor remediation.
- Identify ROX II deployments that use VRF so they can be prioritized for validation and remediation.
- Review Siemens advisory SSA-912274 and CISA advisory ICSA-26-015-11 for device-specific guidance and any deployment notes.
- Apply standard ICS defense-in-depth practices referenced by CISA while remediation is being planned and executed.
Evidence notes
All substantive claims in this debrief come from the supplied CISA CSAF metadata for ICSA-26-015-11 and its listed Siemens references. The advisory text states: 'Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user.' The remediation listed in the corpus is 'Update to V2.17.0 or later version.' No KEV entry was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-56839 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-56839
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-56839 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-56839
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-11.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-912274.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-912274.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-015-11.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-11
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.