Junglewise Threat Intelligence

CVE-2026-41551: Siemens ROS# path traversal in file_server

CVE-2026-41551 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Vendors: Siemens.

Executive brief

Siemens ROS# is a library used to integrate ROS (Robot Operating System) with .NET applications, commonly used in industrial automation and manufacturing. A security flaw in its file server component allows an attacker to remotely read or write sensitive files on the host system. This could lead to the theft of proprietary data or the unauthorized modification of system configurations, potentially disrupting manufacturing operations.

Technical details

A relative path traversal vulnerability (CWE-23) exists in the file_server service of Siemens ROS# before version 2.2.2. The vulnerability stems from insufficient sanitization of user-provided input used in file operations. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the service to access or overwrite files outside of the intended directory, limited only by the permissions of the user account running the service. This can result in full compromise of data confidentiality and integrity on the host system. Siemens has released version 2.2.2 to address this issue.

Affected products

  • Siemens ROS# (ros-sharp) < 2.2.2

Timeline

  • 2026-05-12: advisory: Initial Siemens ProductCERT advisory (SSA-357982) published
  • 2026-05-14: advisory: CISA ICSA-26-134-08 published
  • 2026-05-12: patched: Version 2.2.2 released

References