CVE-2024-56838

Publication date

2025-12-09 10:44:17

Family

siemens

State

PUBLISHED

Description

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2.17.0). The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user.