Unit42 • 3h
AI-Driven Exploit Acceleration Exposes Siemens ROX II Zero-Day to Unauthenticated Root Access
Unit 42 disclosed an unauthenticated stack‑based buffer overflow in the Siemens ROX II web service (CVE‑2024‑XXXX) affecting firmware versions 2.3.0 through 2.5.1. The flaw resides in a fixed‑size HTTP‑header parser (~1 KB) that lacks length checks, allowing remote attackers to overwrite the return address with >2 KB of header data and execute root‑privileged shellcode on the underlying Linux‑based OT controller. Large language models can generate a functional Python exploit in under 15 minutes, collapsing traditional reverse‑engineering timelines and exposing >12 000 deployed controllers to immediate compromise.