CVE-2024-56838

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_rox_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rox_ii:-:*:*:*:*:*:*:*

History

11 Dec 2025, 15:58

Type Values Removed Values Added
First Time Siemens ruggedcom Rox Ii
Siemens
Siemens ruggedcom Rox Ii Firmware
CPE cpe:2.3:h:siemens:ruggedcom_rox_ii:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rox_ii_firmware:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-912274.html - () https://cert-portal.siemens.com/productcert/html/ssa-912274.html - Vendor Advisory

09 Dec 2025, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 16:17

Updated : 2025-12-11 15:58


NVD link : CVE-2024-56838

Mitre link : CVE-2024-56838

CVE.ORG link : CVE-2024-56838


JSON object : View

Products Affected

siemens

  • ruggedcom_rox_ii_firmware
  • ruggedcom_rox_ii
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')