CVE-2025-33023
BaseFortify
Publication date: 2025-08-12
Last updated on: 2025-08-12
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | ruggedcom_rox_mx5000 | * |
| siemens | ruggedcom_rox_rx5000 | * |
| siemens | ruggedcom_rox_rx1500 | * |
| siemens | ruggedcom_rox_mx5000re | * |
| siemens | ruggedcom_rox_rx1536 | * |
| siemens | ruggedcom_rox_rx1400 | * |
| siemens | ruggedcom_rox_rx1524 | * |
| siemens | ruggedcom_rox_rx1512 | * |
| siemens | ruggedcom_rox_rx1511 | * |
| siemens | ruggedcom_rox_rx1510 | * |
| siemens | ruggedcom_rox_rx1501 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects Siemens RUGGEDCOM ROX II devices and occurs because the devices do not properly enforce restrictions on the type and size of files that can be uploaded via their web interface. An authenticated attacker with high privileges on the web interface can exploit this flaw to upload arbitrary files to the device's filesystem. This could potentially impact the integrity of the device but does not affect confidentiality or availability. [1]
How can this vulnerability impact me? :
If exploited, this vulnerability allows an attacker with high privileges on the device's web interface to upload arbitrary files, which could lead to limited integrity impact on the device. This means the attacker might alter or add files on the device, potentially affecting its operation or behavior. However, confidentiality and availability are not impacted by this vulnerability. [1]
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, restrict highly privileged web interface access to authorized and trusted personnel only. Additionally, protect network access with appropriate security mechanisms and configure the operational environment according to Siemens' Industrial Security guidelines. Since no fixes are currently available, applying these recommended mitigations is essential to reduce risk. [1]