unit42 · Crawled Jul 17, 2026
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Read original article ↗AI Summary
Palo Alto Networks and Siemens collaborated to identify a chained exploit involving three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) in Siemens ROX II OT switches. The attack chain begins with arbitrary file disclosure, enables privilege escalation via command injection, and establishes persistent root-level access through the task scheduler. These vulnerabilities allow an unauthenticated attacker to gain full control of critical OT switches, potentially disrupting industrial operations. Siemens has released firmware updates, and virtual patching is available via Palo Alto Networks.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.