DEV Community

Mark0
Mark0

Posted on

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

⚠️ Region Alert: UAE/Middle East

Researchers from Palo Alto Networks Unit 42 and Siemens have disclosed a critical exploit chain involving three zero-day vulnerabilities in Siemens ROX II operational technology (OT) switches. The chain—comprising CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949—enables an attacker to escalate from initial reconnaissance to full persistent root-level access. These switches are vital components in industrial control networks, serving as the communication backbone for critical assets like HMIs and PLCs.

The attack progresses through arbitrary file disclosure via the xz utility, privilege escalation through command injection in feature key validation, and finally, persistence via the system's task scheduler. Siemens has released firmware version V2.17.1 to mitigate these risks. Organizations are advised to update affected devices immediately or utilize virtual patching and advanced threat prevention services to secure their OT environments.


Read Full Article

Top comments (0)