Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
ID: 99afba6e-3531-56ed-8df1-33e801aad134
STIX ID: report--99afba6e-3531-56ed-8df1-33e801aad134
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-07-17
Date Updated: 2026-07-23
Author: Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira
Palo Alto Networks in partnership with Siemens disclosed a chained set of three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational-technology switches that together allow arbitrary file disclosure via misuse of xz, root privilege escalation through feature-key command injection, and persistent root execution via task-scheduler injection; Siemens released advisories and a firmware update (V2.17.1) while Palo Alto recommends defenses and provides detection/mitigation guidance and indicators of behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
