Patch Tuesday
December 2025
On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.
How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.
224 records · 1 KEV
Affecting your stack
This month's records that match the products and versions in your stack.
Sign in to see the ones matching your stack; records and notifications are free. →
Microsoft · December 9
56 · 1 KEV · 1 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2025-62221Weaponized | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-416 | High7.8 | KEV | 2.5% | Dec 9, 2025 |
36Monitor | CVE-2025-64672No exploit | Microsoft SharePoint Server Spoofing Vulnerabilitymicrosoft · sharepoint server · CWE-79 | Critical9.0 | — | 1.0% | Dec 9, 2025 |
35Monitor | CVE-2025-62456No exploit | Windows Resilient File System (ReFS) Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-122 | High8.8 | — | 1.1% | Dec 9, 2025 |
35Monitor | CVE-2025-62549No exploit | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-822 | High8.8 | — | 1.3% | Dec 9, 2025 |
35Monitor | CVE-2025-62550No exploit | Azure Monitor Agent Remote Code Execution Vulnerabilitymicrosoft · azure monitor agent · CWE-131 | High8.8 | — | 0.7% | Dec 9, 2025 |
35Monitor | CVE-2025-64678No exploit | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High8.8 | — | 1.0% | Dec 9, 2025 |
32Monitor | CVE-2025-54100Proof of concept | PowerShell Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-77 | High7.8 | — | 2.2% | Dec 9, 2025 |
32Monitor | CVE-2025-59516No exploit | Windows Storage VSP Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-73 | High7.8 | — | 2.3% | Dec 9, 2025 |
32Monitor | CVE-2025-59517No exploit | Windows Storage VSP Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-284 | High7.8 | — | 2.5% | Dec 9, 2025 |
32Monitor | CVE-2025-62454Proof of concept | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-122 | High7.8 | — | 2.3% | Dec 9, 2025 |
32Monitor | CVE-2025-62472No exploit | Windows Remote Access Connection Manager Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | High7.8 | — | 2.2% | Dec 9, 2025 |
31Monitor | CVE-2025-55233No exploit | Windows Projected File System Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-125 | High7.8 | — | 0.4% | Dec 9, 2025 |
- CVE-2025-6222162This week
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 3%microsoft · windows 10 1809Dec 9, 2025
- CVE-2025-6467236Monitor
Microsoft SharePoint Server Spoofing Vulnerability
CriticalCVSS 9.0No exploitEPSS 1%microsoft · sharepoint serverDec 9, 2025
- CVE-2025-6245635Monitor
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 11 23h2Dec 9, 2025
- CVE-2025-6254935Monitor
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Dec 9, 2025
- CVE-2025-6255035Monitor
Azure Monitor Agent Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · azure monitor agentDec 9, 2025
- CVE-2025-6467835Monitor
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Dec 9, 2025
- CVE-2025-5410032Monitor
PowerShell Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 2%microsoft · windows 10 1607Dec 9, 2025
- CVE-2025-5951632Monitor
Windows Storage VSP Driver Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 2%microsoft · windows 10 1809Dec 9, 2025
- CVE-2025-5951732Monitor
Windows Storage VSP Driver Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 2%microsoft · windows 10 1607Dec 9, 2025
- CVE-2025-6245432Monitor
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
HighCVSS 7.8Proof of conceptEPSS 2%microsoft · windows 10 1809Dec 9, 2025
- CVE-2025-6247232Monitor
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 2%microsoft · windows 10 1607Dec 9, 2025
- CVE-2025-5523331Monitor
Windows Projected File System Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 0%microsoft · windows 10 1809Dec 9, 2025
+44 moreAll records of the vendor
Adobe · December 9
135 · 0 KEV · 6 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-61808No exploit | ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)adobe · coldfusion · CWE-434 | Critical9.1 | — | 10.6% | Dec 9, 2025 |
37Monitor | CVE-2025-64537No exploit | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)adobe · experience manager · CWE-79 | Critical9.3 | — | 0.7% | Dec 10, 2025 |
37Monitor | CVE-2025-64538No exploit | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)adobe · experience manager · CWE-79 | Critical9.3 | — | 0.6% | Dec 10, 2025 |
37Monitor | CVE-2025-64539No exploit | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)adobe · experience manager · CWE-79 | Critical9.3 | — | 0.5% | Dec 10, 2025 |
36Monitor | CVE-2025-61809No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Critical9.1 | — | 0.7% | Dec 9, 2025 |
36Monitor | CVE-2025-61810No exploit | ColdFusion | Deserialization of Untrusted Data (CWE-502)adobe · coldfusion · CWE-502 | High8.4 | — | 9.5% | Dec 9, 2025 |
36Monitor | CVE-2025-61811No exploit | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | Critical9.1 | — | 1.2% | Dec 9, 2025 |
34Monitor | CVE-2025-61812No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | High8.4 | — | 4.7% | Dec 9, 2025 |
31Monitor | CVE-2025-64783No exploit | DNG SDK | Integer Overflow or Wraparound (CWE-190)adobe · dng software development kit · CWE-190 | High7.8 | — | 0.2% | Dec 9, 2025 |
31Monitor | CVE-2025-64785No exploit | Acrobat Reader | Untrusted Search Path (CWE-426)adobe · acrobat · CWE-426 | High7.8 | — | 0.5% | Dec 9, 2025 |
31Monitor | CVE-2025-64899No exploit | Acrobat Reader | Out-of-bounds Read (CWE-125)adobe · acrobat · CWE-125 | High7.8 | — | 0.5% | Dec 9, 2025 |
29Monitor | CVE-2025-61813No exploit | ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)adobe · coldfusion · CWE-611 | High7.4 | — | 0.5% | Dec 9, 2025 |
- CVE-2025-6180839Monitor
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CriticalCVSS 9.1No exploitEPSS 11%adobe · coldfusionDec 9, 2025
- CVE-2025-6453737Monitor
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · experience managerDec 10, 2025
- CVE-2025-6453837Monitor
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · experience managerDec 10, 2025
- CVE-2025-6453937Monitor
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 0%adobe · experience managerDec 10, 2025
- CVE-2025-6180936Monitor
ColdFusion | Improper Input Validation (CWE-20)
CriticalCVSS 9.1No exploitEPSS 1%adobe · coldfusionDec 9, 2025
- CVE-2025-6181036Monitor
ColdFusion | Deserialization of Untrusted Data (CWE-502)
HighCVSS 8.4No exploitEPSS 10%adobe · coldfusionDec 9, 2025
- CVE-2025-6181136Monitor
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CriticalCVSS 9.1No exploitEPSS 1%adobe · coldfusionDec 9, 2025
- CVE-2025-6181234Monitor
ColdFusion | Improper Input Validation (CWE-20)
HighCVSS 8.4No exploitEPSS 5%adobe · coldfusionDec 9, 2025
- CVE-2025-6478331Monitor
DNG SDK | Integer Overflow or Wraparound (CWE-190)
HighCVSS 7.8No exploitEPSS 0%adobe · dng software development kitDec 9, 2025
- CVE-2025-6478531Monitor
Acrobat Reader | Untrusted Search Path (CWE-426)
HighCVSS 7.8No exploitEPSS 0%adobe · acrobatDec 9, 2025
- CVE-2025-6489931Monitor
Acrobat Reader | Out-of-bounds Read (CWE-125)
HighCVSS 7.8No exploitEPSS 0%adobe · acrobatDec 9, 2025
- CVE-2025-6181329Monitor
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
HighCVSS 7.4No exploitEPSS 1%adobe · coldfusionDec 9, 2025
+123 moreAll records of the vendor
SAP · December 9
12 · 0 KEV · 2 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-42880No exploit | Code Injection vulnerability in SAP Solution Managersap_se · sap solution manager · CWE-94 | Critical9.9 | — | 4.5% | Dec 9, 2025 |
39Monitor | CVE-2025-42928No exploit | Deserialization Vulnerability in SAP jConnect - SDK for ASEsap_se · sap jconnect - sdk for ase · CWE-502 | Critical9.1 | — | 9.5% | Dec 9, 2025 |
32Monitor | CVE-2025-42878No exploit | Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)sap_se · sap web dispatcher and internet communication manager (icm) · CWE-1244 | High8.2 | — | 0.4% | Dec 9, 2025 |
31Monitor | CVE-2025-42874No exploit | Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)sap_se · sap netweaver (remote service for xcelsius) · CWE-405 | High7.9 | — | 0.5% | Dec 9, 2025 |
30Monitor | CVE-2025-42877No exploit | Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Serversap_se · sap web dispatcher, internet communication manager and sap content server · CWE-787 | High7.5 | — | 0.5% | Dec 9, 2025 |
28Monitor | CVE-2025-42876No exploit | Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)sap_se · sap s/4 hana private cloud (financials general ledger) · CWE-405 | High7.1 | — | 0.3% | Dec 9, 2025 |
26Monitor | CVE-2025-42875No exploit | Missing Authentication check in SAP NetWeaver Internet Communication Frameworksap_se · sap netweaver internet communication framework · CWE-306 | Medium6.6 | — | 0.3% | Dec 9, 2025 |
26Monitor | CVE-2025-42904No exploit | Information Disclosure vulnerability in Application Server ABAPsap_se · application server abap · CWE-549 | Medium6.5 | — | 0.3% | Dec 9, 2025 |
24Monitor | CVE-2025-42872No exploit | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portalsap_se · sap netweaver enterprise portal · CWE-489 | Medium6.1 | — | 0.3% | Dec 9, 2025 |
23Monitor | CVE-2025-42873No exploit | Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)sap_se · sapui5 framework (markdown-it component) · CWE-405 | Medium5.9 | — | 0.4% | Dec 9, 2025 |
22Monitor | CVE-2025-42891No exploit | Missing Authorization check in SAP Enterprise Search for ABAPsap_se · sap enterprise search for abap · CWE-862 | Medium5.5 | — | 0.3% | Dec 9, 2025 |
21Monitor | CVE-2025-42896No exploit | Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platformsap_se · sap businessobjects business intelligence platform · CWE-116 | Medium5.4 | — | 0.3% | Dec 9, 2025 |
- CVE-2025-4288040Plan
Code Injection vulnerability in SAP Solution Manager
CriticalCVSS 9.9No exploitEPSS 5%sap_se · sap solution managerDec 9, 2025
- CVE-2025-4292839Monitor
Deserialization Vulnerability in SAP jConnect - SDK for ASE
CriticalCVSS 9.1No exploitEPSS 9%sap_se · sap jconnect - sdk for aseDec 9, 2025
- CVE-2025-4287832Monitor
Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
HighCVSS 8.2No exploitEPSS 0%sap_se · sap web dispatcher and internet communication manager (icm)Dec 9, 2025
- CVE-2025-4287431Monitor
Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
HighCVSS 7.9No exploitEPSS 0%sap_se · sap netweaver (remote service for xcelsius)Dec 9, 2025
- CVE-2025-4287730Monitor
Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
HighCVSS 7.5No exploitEPSS 1%sap_se · sap web dispatcher, internet communication manager and sap content serverDec 9, 2025
- CVE-2025-4287628Monitor
Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)
HighCVSS 7.1No exploitEPSS 0%sap_se · sap s/4 hana private cloud (financials general ledger)Dec 9, 2025
- CVE-2025-4287526Monitor
Missing Authentication check in SAP NetWeaver Internet Communication Framework
MediumCVSS 6.6No exploitEPSS 0%sap_se · sap netweaver internet communication frameworkDec 9, 2025
- CVE-2025-4290426Monitor
Information Disclosure vulnerability in Application Server ABAP
MediumCVSS 6.5No exploitEPSS 0%sap_se · application server abapDec 9, 2025
- CVE-2025-4287224Monitor
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
MediumCVSS 6.1No exploitEPSS 0%sap_se · sap netweaver enterprise portalDec 9, 2025
- CVE-2025-4287323Monitor
Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)
MediumCVSS 5.9No exploitEPSS 0%sap_se · sapui5 framework (markdown-it component)Dec 9, 2025
- CVE-2025-4289122Monitor
Missing Authorization check in SAP Enterprise Search for ABAP
MediumCVSS 5.5No exploitEPSS 0%sap_se · sap enterprise search for abapDec 9, 2025
- CVE-2025-4289621Monitor
Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform
MediumCVSS 5.4No exploitEPSS 0%sap_se · sap businessobjects business intelligence platformDec 9, 2025
Siemens · December 9
21 · 0 KEV · 3 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2025-40800No exploit | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < siemens · comos v10.6 · CWE-295 | Critical9.1 | — | 0.2% | Dec 9, 2025 |
36Monitor | CVE-2025-40801No exploit | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translasiemens · comos v10.6 · CWE-295 | Critical9.2 | — | 0.3% | Dec 9, 2025 |
36Monitor | CVE-2025-40938No exploit | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).siemens · simatic cn 4100 firmware · CWE-798 | Critical9.2 | — | 0.4% | Dec 9, 2025 |
34Monitor | CVE-2024-56835No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-74 | High8.7 | — | 0.5% | Dec 9, 2025 |
34Monitor | CVE-2024-56837No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-77 | High8.6 | — | 0.5% | Dec 9, 2025 |
34Monitor | CVE-2024-56838No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-74 | High8.6 | — | 0.4% | Dec 9, 2025 |
34Monitor | CVE-2024-56839No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-74 | High8.6 | — | 0.6% | Dec 9, 2025 |
34Monitor | CVE-2025-40820No exploit | Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.siemens · sidoor atd430w · CWE-940 | High8.7 | — | 0.5% | Dec 9, 2025 |
34Monitor | CVE-2025-40937No exploit | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).siemens · simatic cn 4100 firmware · CWE-77 | High8.7 | — | 0.6% | Dec 9, 2025 |
33Monitor | CVE-2025-40830No exploit | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0).siemens · sinec security monitor · CWE-285 | High8.4 | — | 0.2% | Dec 9, 2025 |
30Monitor | CVE-2024-56836No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-77 | High7.7 | — | 0.4% | Dec 9, 2025 |
30Monitor | CVE-2024-56840No exploit | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEsiemens · ruggedcom rox ii firmware · CWE-74 | High7.5 | — | 0.6% | Dec 9, 2025 |
- CVE-2025-4080036Monitor
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions <
CriticalCVSS 9.1No exploitEPSS 0%siemens · comos v10.6Dec 9, 2025
- CVE-2025-4080136Monitor
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Transla
CriticalCVSS 9.2No exploitEPSS 0%siemens · comos v10.6Dec 9, 2025
- CVE-2025-4093836Monitor
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).
CriticalCVSS 9.2No exploitEPSS 0%siemens · simatic cn 4100 firmwareDec 9, 2025
- CVE-2024-5683534Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 8.7No exploitEPSS 1%siemens · ruggedcom rox ii firmwareDec 9, 2025
- CVE-2024-5683734Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 8.6No exploitEPSS 1%siemens · ruggedcom rox ii firmwareDec 9, 2025
- CVE-2024-5683834Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 8.6No exploitEPSS 0%siemens · ruggedcom rox ii firmwareDec 9, 2025
- CVE-2024-5683934Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 8.6No exploitEPSS 1%siemens · ruggedcom rox ii firmwareDec 9, 2025
- CVE-2025-4082034Monitor
Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.
HighCVSS 8.7No exploitEPSS 0%siemens · sidoor atd430wDec 9, 2025
- CVE-2025-4093734Monitor
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).
HighCVSS 8.7No exploitEPSS 1%siemens · simatic cn 4100 firmwareDec 9, 2025
- CVE-2025-4083033Monitor
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0).
HighCVSS 8.4No exploitEPSS 0%siemens · sinec security monitorDec 9, 2025
- CVE-2024-5683630Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 7.7No exploitEPSS 0%siemens · ruggedcom rox ii firmwareDec 9, 2025
- CVE-2024-5684030Monitor
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE
HighCVSS 7.5No exploitEPSS 1%siemens · ruggedcom rox ii firmwareDec 9, 2025
+9 moreAll records of the vendor
Schneider Electric · December 9
0 · 0 KEV · 0 criticalNo records in this window.