CVE-2024-38278Network attack vector

Remote shell via unintended cross-VLAN service exposure

Published Jul 9, 2024 · Updated Aug 27, 2025

Incorrect privilege assignment in Siemens RUGGEDCOM ROS before 5.9.0 allows remote authenticated users to create a remote shell. With IP forwarding enabled, the firmware exposes remote services in non-managed VLANs even when those services were not intentionally activated. Exploitation requires high privileges and the non-default IP-forwarding configuration, but grants control of the appliance.

CVSS severity7.5
High
EPSS probability0.34%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Incorrect privilege assignment in Siemens RUGGEDCOM ROS before 5.9.0 allows remote authenticated users to create a remote shell. With IP forwarding enabled, the firmware exposes remote services in non-managed VLANs even when those services were not intentionally activated. Exploitation requires high privileges and the non-default IP-forwarding configuration, but grants control of the appliance.

The record

CVE
CVE-2024-38278
Published
Jul 9, 2024
Updated
Aug 27, 2025
Vendor
Siemens
Product
RUGGEDCOM ROS RS416NCv2
Classifications
CWE-266, T1021
Attack vector
network
Privileges
admin

Timeline

How it unfolded

  1. Jul 9, 2024CVE publishedPublication date reported by the CVE source.
  2. Aug 27, 2025Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <5.9.0

What conditions does exploitation require?

Attack vectornetwork
Required privilegesadmin

What is affected?

Siemens · RUGGEDCOM ROS RS416NCv2version=0 <5.9.0
Siemens · RUGGEDCOM RSG2288version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSL910NCversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2100NC (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM RS416Pv2version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSL910version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG2100NCversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2488version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RS900GNCversion=0 <5.9.0
Siemens · RUGGEDCOM RST2228version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2488version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG920Pversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2100P (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM RSG909Rversion=0 <V5.9.0
Siemens · RUGGEDCOM RST916Cversion=0 <V5.9.0
Siemens · RUGGEDCOM RSG2300NCversion=0 <V5.9.0
Siemens · RUGGEDCOM RSG2300version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG909Rversion=0 <5.9.0
Siemens · RUGGEDCOM RS900GNC (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2300Pversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RMC8388version=0 <5.9.0
Siemens · RUGGEDCOM RS416PNCv2version=0 <V5.9.0
Siemens · RUGGEDCOM RSG2100PNC (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RST916Pversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG920PNCversion=0 <5.9.0
Siemens · RUGGEDCOM RSG910Cversion=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2300NCversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RS416v2version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG910Cversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2288NCversion=0 <V5.9.0
Siemens · RUGGEDCOM RS900G (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM RST916Pversion=0 <V5.9.0
Siemens · RUGGEDCOM RSG908Cversion=0 <V5.9.0
Siemens · RUGGEDCOM RS900NC (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM RSG2100 (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM RSG920Pversion=0 <V5.9.0
Siemens · RUGGEDCOM RSG2488NCversion=0 <V5.9.0
Siemens · RUGGEDCOM RSG920PNCversion=0 <V5.9.0
Siemens · RUGGEDCOM RST2228Pversion=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2288NCversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG907Rversion=0 <5.9.0
Siemens · RUGGEDCOM RS416v2version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RST2228version=0 <5.9.0
Siemens · RUGGEDCOM ROS RS900version=0 <5.9.0
Siemens · RUGGEDCOM ROS RS900Gversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2300PNCversion=0 <V5.9.0
Siemens · RUGGEDCOM RSL910version=0 <V5.9.0
Siemens · RUGGEDCOM RS416NCv2version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2300PNCversion=0 <5.9.0
Siemens · RUGGEDCOM RMC8388version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RS416PNCv2version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG2288version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG2300version=0 <5.9.0
Siemens · RUGGEDCOM ROS RS416Pv2version=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG908Cversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RMC8388NCversion=0 <5.9.0
Siemens · RUGGEDCOM RMC8388NCversion=0 <V5.9.0
Siemens · RUGGEDCOM ROS RST2228Pversion=0 <5.9.0
Siemens · RUGGEDCOM RSG907Rversion=0 <V5.9.0
Siemens · RUGGEDCOM RS900 (32M)version=0 <V5.9.0
Siemens · RUGGEDCOM ROS RSG2488NCversion=0 <5.9.0
Siemens · RUGGEDCOM RSL910NCversion=0 <V5.9.0
Siemens · RUGGEDCOM ROS RST916Cversion=0 <5.9.0
Siemens · RUGGEDCOM ROS RSG2100version=0 <5.9.0
Siemens · RUGGEDCOM ROS RS900NCversion=0 <5.9.0
Siemens · RUGGEDCOM RSG2300Pversion=0 <V5.9.0

Published CVSS scores

7.5Siemens ProductCERTCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
6.6Siemens ProductCERTCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectornetwork
Privilegesadmin
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-266Incorrect Privilege Assignment
T1021Remote Services

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo