CVE-2026-41551

CRITICAL

View CSAF Summary ROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary ...

Affects 0 products across 2 vendors.

BCS6.33
CVSS 3.19.1
CVSS v49.3
EPSS0.5%
Percentile39th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-23: CWE-23
Related Attack Patterns (CAPEC)
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-23
CAPEC-139 Relative Path Traversal
via CWE-23

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens ROS# service file_server in versions prior to 2.2.2 contains a path traversal vulnerability, allowing attackers to read and write arbitrary files on the system. This poses significant risks to the integrity and confidentiality of the system. Siemens recommends updating to the latest version to mitigate this vulnerability.

BSID: BS-2026-GLOBAL-296561-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-41551?
The Siemens ROS# service file_server in versions prior to 2.2.2 contains a path traversal vulnerability, allowing attackers to read and write arbitrary files on the system. This poses significant risks to the integrity and confidentiality of the system. Siemens recommends updating to the latest version to mitigate this vulnerability.
What is the CVSS score for CVE-2026-41551?
CVE-2026-41551 has CVSS 9.1 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. EPSS: 0.5%.
Is CVE-2026-41551 actively exploited?
No confirmed active exploitation of CVE-2026-41551 as of 2026-05-30.
How do I remediate CVE-2026-41551?
Priority: HIGH.
What systems are affected by CVE-2026-41551?
CVE-2026-41551 affects: Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2026-41551?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to critical cyber assets, compromising the integrity and confidentiality of the system.
What IEC 62443 requirement maps to CVE-2026-41551?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to system resources, which is a key security requirement for protecting against such threats.
Vulnerability Details
CVE IDCVE-2026-41551
BSIDBS-2026-GLOBAL-296561-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published2026-05-14
Last Modified2026-05-14
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary ROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary files, which are accessible with the user rights of the user that runs the service, on the system that hosts service. Siemens has released a new version for ROS# and recommends to update to the latest version. The following versions of Siemens Siemens ROS# are affected: ROS# vers:intdot/<2.2.2 CVSS Ven

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely without authentication, requiring low skill level. An attacker can leverage this vulnerability to traverse directories and access sensitive files, potentially leading to unauthorized modifications or data exfiltration.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens &mdash;
Siemens &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all file paths used by the ROS# service. Restrict the service's file system access to a designated directory with minimal permissions.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to critical cyber assets, compromising the integrity and confidentiality of the system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to system resources, which is a key security requirement for protecting against such threats.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashc76e719f135e12d484036d34c2a87817b25cc6491e9b57daf4d16ecef646aa7e1622339a84b016f1687344a9cc38046c93fa8ffb35eef5a8014a0468521a9da3
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →