Critical Siemens ROS# Flaw Enables Arbitrary File Access and Host Takeover
ID: f17fd4f5-7167-5e33-bb17-18ec780ebfe9
STIX ID: report--f17fd4f5-7167-5e33-bb17-18ec780ebfe9
Feed Name: securityonline.info
Threat Score
**Executive summary:** Siemens ProductCERT disclosed CVE-2026-41551, a critical (CVSS v4.0 9.3) path traversal vulnerability in the ROS# file_server that can allow remote attackers to read and write arbitrary files on hosts; Siemens recommends updating to ROS# V2.2.2 or applying mitigations (isolate the service, run with least privileges, restrict operational use, and prefer manual transfers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
