Siemens Siemens ROS#
This advisory details a critical vulnerability in Siemens ROS# (version 2.2.2 and earlier) due to a path traversal flaw. An attacker could potentially access and modify arbitrary files on a system hosting the ROS# file_server service, posing a risk to critical manufacturing operations. Siemens recommends immediate updating to version 2.2.2 or later to mitigate this threat.
The vulnerability stems from improper input sanitization within the ROS# file_server service. Specifically, versions prior to 2.2.2 are susceptible to a path traversal attack, allowing a remote attacker to navigate outside the intended file system directories and access sensitive files. This could lead to data breaches, system compromise, or the deployment of malicious software. The CISA recommends immediate action to address this risk, emphasizing the importance of network segmentation and secure configurations for industrial control systems.