ICSA-26-134-16: Siemens Ruggedcom Rox
CISA advisory · released 2026-05-12
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 2, 2026-05-14 (final)
CISA's summary
Summary: Ruggedcom Rox before v2.17.1 contain multiple third-party vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | RUGGEDCOM ROX MX5000 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX MX5000RE | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1400 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1500 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1501 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1510 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1511 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1512 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1524 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX1536 | vers:intdot/<2.17.1 |
| Siemens | RUGGEDCOM ROX RX5000 | vers:intdot/<2.17.1 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2019-13103 — CVE-2019-13103 · CWE-674
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.
- CVE-2019-13104 — CVE-2019-13104 · CWE-191
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
- CVE-2019-13106 — CVE-2019-13106 · CWE-787
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
- CVE-2019-14192 — CVE-2019-14192 · CWE-191
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.
- CVE-2019-14193 — CVE-2019-14193 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.
- CVE-2019-14194 — CVE-2019-14194 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.
- CVE-2019-14195 — CVE-2019-14195 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.
- CVE-2019-14196 — CVE-2019-14196 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply.
- CVE-2019-14197 — CVE-2019-14197 · CWE-125
An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.
- CVE-2019-14198 — CVE-2019-14198 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case.
- CVE-2019-14199 — CVE-2019-14199 · CWE-191
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.
- CVE-2019-14200 — CVE-2019-14200 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.
- CVE-2019-14201 — CVE-2019-14201 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.
- CVE-2019-14202 — CVE-2019-14202 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.
- CVE-2019-14203 — CVE-2019-14203 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.
- CVE-2019-14204 — CVE-2019-14204 · CWE-787
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.
- CVE-2020-10648 — CVE-2020-10648 · CWE-20
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
- CVE-2022-2347 — CVE-2022-2347 · CWE-122
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
- CVE-2022-30552 — CVE-2022-30552 · CWE-120
Das U-Boot 2022.01 has a Buffer Overflow.
- CVE-2022-30790 — CVE-2022-30790 · CWE-787
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
- CVE-2022-34835 — CVE-2022-34835 · CWE-787
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
- CVE-2023-3019 — CVE-2023-3019 · CWE-416
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
- CVE-2023-27043 — CVE-2023-27043 · CWE-1286
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
- CVE-2024-3447 — CVE-2024-3447 · CWE-122
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
- CVE-2024-22365 — CVE-2024-22365 · CWE-664
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
- CVE-2024-57256 — CVE-2024-57256 · CWE-190
An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
- CVE-2024-57258 — CVE-2024-57258 · CWE-190
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.
- CVE-2025-0395 — CVE-2025-0395 · CWE-131
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
- CVE-2025-3576 — CVE-2025-3576 · CWE-328
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
- CVE-2025-6020 — CVE-2025-6020 · CWE-22
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
- CVE-2025-7425 — CVE-2025-7425 · CWE-416
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
- CVE-2025-9714 — CVE-2025-9714 · CWE-674
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
- CVE-2025-46836 — CVE-2025-46836 · CWE-121
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when showing interfaces. `get_name()` in `interface.c` copies interface labels from `/proc/net/dev` into a fixed 16-byte stack buffer without bounds checking, leading to possible arbitrary code execution or crash. The known attack path does not require privilege but also does not provide privilege escalation in this scenario. A patch is available and expected to be part of version 2.20.
- CVE-2025-49794 — CVE-2025-49794 · CWE-825
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
- CVE-2025-49796 — CVE-2025-49796 · CWE-125
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reported these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.