These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Based on the advisory metadata and linked vendor/CISA publications, CVE-2025-68686 affects Siemens RUGGEDCOM APE1808 and describes a post-exploitation exposure: a remote unauthenticated attacker may use crafted HTTP requests to bypass a patch intended to address symbolic-link persistency. The source notes say the attacker would first need filesystem-level compromise through another vulnerability, so this [truncated]
A critical vulnerability has been identified in Mendix Runtime, affecting access rule configuration. The Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, potentially leading to overly permissive access rules and unintended exposure of sensitive user data or privilege escalation. This issue may impact Mendix application developers who have n [truncated]
A critical vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header, allowing an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms, and impersonate any user, including administrative accounts. This could potentially grant full unauthorized access t [truncated]
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application become [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T10:16:30.783Z and has not been modified since then. A vulnerability in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. The CVSS score is 8.5, indicating high severity. Users of COMOS V10.4.5, COMOS V10.6, Designcenter NX, Simcenter 3D [truncated]
CVE-2025-40022 is a Linux kernel af_alg logic issue in which fields changed from bool to 1-bit u32 bitfields can store the wrong value when assignments greater than 1 are used. In the supplied advisory corpus, CISA’s Siemens CSAF entry tracks the issue under the SIMATIC S7-1500 CPU family and states that no fix is available at the time of the advisory updates. The published CVSS v3.1 score is 5.3 (Medium) [truncated]
CVE-2025-39977 is a Linux kernel futex use-after-free in the requeue-PI path that Siemens included in its SIMATIC S7-1500 advisory. The supplied advisory data rates it HIGH (CVSS 7.0) and indicates there is currently no fix, so affected operators should rely on compensating controls until vendor guidance changes.
CVE-2025-39931 is a Linux kernel af_alg state-handling flaw that can leave ctx->merge with stale data after an aborted af_alg_sendmsg call. On a later call, that bad state can trigger an invalid merge attempt and crash the affected Linux path. In the Siemens advisory, the issue is mapped to SIMATIC S7-1500 CPU family products that include an additional GNU/Linux subsystem.
CVE-2025-26465 affects multiple Siemens SIMATIC S7-1500 CPU family products and is tied to OpenSSH behavior when VerifyHostKeyDNS is enabled. According to the advisory, a successful machine-in-the-middle attack requires the attacker to first exhaust the client’s memory resources, which raises the attack complexity, and Siemens notes that no fix is currently available.
CVE-2025-21864 is a Linux kernel availability issue affecting Siemens SIMATIC S7-1500 CPU 1518 MFP-family products in the supplied advisory. The reported bug can leave a secpath-linked reference to xfrm_state attached to an skb during deferred cleanup, so the reference is still present when a network namespace is deleted. In the source description, this can trigger a WARN in xfrm6_tunnel_net_exit during T [truncated]
CVE-2025-21846 is a MEDIUM severity vulnerability (CVSS 5.5) affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability involves the Linux kernel's process accounting (acct) subsystem, where the last write operation is performed from a workqueue context. This local attack vector vulnerability requires low privileges and no user interaction, with avail [truncated]
A vulnerability in the Linux kernel's PTP (Precision Time Protocol) subsystem affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial controllers. The issue stems from a missing validation that the `info->enable` callback is set before invocation, which can lead to a NULL pointer dereference. This local vulnerability requires low privileges to exploit and results in high availability [truncated]
The supplied advisory data ties CVE-2025-21796 to five Siemens SIMATIC/SIPLUS S7-1500 CPU variants and describes a local availability issue in nfsd ACL handling. Siemens/CISA rate it CVSS 5.5 (medium) with high availability impact, no confidentiality or integrity impact, and no current fix available. For OT environments, the practical priority is to reduce exposure of the GNU/Linux subsystem and limit who [truncated]
CVE-2025-21795 is an availability issue in the NFSD shutdown path that can leave nfsd4_shutdown_callback waiting when an nfs4_client is in courtesy state. In Siemens’ advisory for the SIMATIC S7-1500 CPU family, the result is a prolonged hang of roughly 15 minutes until TCP indicates the connection was dropped. CISA republishes the Siemens advisory for the affected CPU variants, and the source set indicat [truncated]
CVE-2025-21765 is a medium-severity availability issue tied to IPv6 handling in ip6_default_advmss(). The source description says the function needs RCU protection so the net structure it reads does not disappear. In the Siemens/CISA advisory corpus, the issue is mapped to five Siemens SIMATIC S7-1500 CPU MFP product variants, with no fix available in the cited advisory and compensating mitigations instead.
CVE-2025-21764 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's IPv6 Neighbor Discovery (NDISC) subsystem. The issue involves missing RCU (Read-Copy-Update) protection in the ndisc_alloc_skb() function, which can lead to use-after-free conditions. This vulnerability was published on April 9, 2024, and most recently modified on May 14, 2026. Siemens has identified this vulnerability [truncated]
CVE-2025-21760 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's IPv6 Neighbor Discovery (NDISC) subsystem. The issue involves insufficient RCU (Read-Copy-Update) protection in the ndisc_send_skb() function, which can lead to use-after-free conditions. The vulnerability was published on 2024-04-09 and last modified on 2026-05-14. Siemens has identified this vulnerability as affectin [truncated]
CVE-2025-21758 is a medium-severity issue described as missing RCU protection in the IPv6 multicast path around mld_newpack(). In the Siemens/CISA advisory context, it applies to specific SIMATIC S7-1500 CPU variants that include an additional GNU/Linux subsystem, with no fix available at publication time.
CVE-2025-21745 is a Linux kernel issue that Siemens and CISA map to the SIMATIC S7-1500 CPU family. The flaw is a refcount leakage in blk-cgroup code: blkcg_fill_root_iostats() iterates through block_class devices but does not end the iteration with class_dev_iter_exit(), which can leak the class subsystem reference count. The advisory characterizes the issue as an availability problem with local attack c [truncated]
CVE-2025-21702 is a high-severity Linux kernel queue-management issue described in Siemens and CISA advisories for the SIMATIC S7-1500 CPU family. The supplied advisory text says a pfifo_tail_enqueue() edge case can increase queue length even when sch->limit is 0 and the queue is empty, violating parent/child qlen accounting. Siemens/CISA state the issue can be used for user-to-kernel privilege escalation [truncated]
A vulnerability in the Linux kernel's netfilter connection tracking (conntrack) subsystem allows triggering a WARN_ON_ONCE warning when resizing the conntrack hashtable. The issue occurs because the hashtable size was not clamped to INT_MAX, and __GFP_NOWARN is unset during allocation. When an oversized allocation is attempted via __kvmalloc_node_noprof(), the kernel emits a warning. The vulnerability is [truncated]
A NULL pointer dereference vulnerability in the UBIFS (Unsorted Block Image File System) implementation of the Linux kernel. The flaw occurs when the TNC (Tree Node Cache) tree dumping routine fails to validate that the zroot pointer is non-NULL before dereferencing it. This can lead to a kernel crash (denial of service) when triggered by a local attacker with low privileges. The vulnerability affects Sie [truncated]
CVE-2024-58020 is a NULL pointer dereference vulnerability in the Linux kernel's HID multitouch driver, specifically in the `mt_input_configured` function. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The flaw occurs when the multitouch input configuration fails to validate a pointer before derefe [truncated]
CVE-2024-58016 is a medium-severity vulnerability (CVSS 5.5) affecting the SafeSetID Linux Security Module (LSM), specifically impacting the GNU/Linux subsystem within Siemens SIMATIC S7-1500 TM MFP industrial control systems. The vulnerability stems from insufficient validation of policy write sizes in the safesetid module, which could allow local attackers to cause denial-of-service conditions. Publishe [truncated]
A use-after-free vulnerability in the Pulse Per Second (PPS) subsystem of the Linux kernel affects the GNU/Linux subsystem embedded in Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw, published 2024-04-09, allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impact without user interaction. The vulnerability stems from improper memory man [truncated]
A use-after-free vulnerability in the Linux kernel's SCSI generic (sg) driver affects Siemens SIMATIC S7-1500 TM MFP industrial control systems. The flaw resides in sg_release(), where improper sequencing of resource cleanup and mutex operations can lead to slab-use-after-free conditions. Discovered by syzbot with KASAN detection, this vulnerability allows a local attacker with low privileges to potential [truncated]
CISA’s advisory for CVE-2024-53124 associates the issue with Siemens SIMATIC S7-1500 TM MFP - BIOS and rates it MEDIUM (CVSS 4.7). The advisory states that no fix is currently available and recommends a workaround focused on trusted software sources. Based on the CVSS vector, the issue requires local access with low privileges, is high complexity, needs no user interaction, and primarily affects availability.
CVE-2023-52927 is published in Siemens’ SIMATIC S7-1500 CPU family advisory and is assessed at medium severity with an availability-only impact profile. The advisory says no fix is currently available for the listed CPU variants. Siemens recommends limiting access to the additional GNU/Linux subsystem to trusted personnel and only building or running applications from trusted sources.
CVE-2023-45853 is a critical memory-corruption flaw tied to MiniZip in zlib through 1.3 and mapped by Siemens to multiple SCALANCE WAB/WAM/WUB/WUM devices. The issue is described as an integer overflow that can lead to a heap-based buffer overflow in zipOpenNewFileInZip4_64 when processing a long filename, comment, or extra field. Siemens’ advisory and the CISA CSAF record were published on 2025-02-11 and [truncated]
The CVE-2026-54800 vulnerability affects Siemens CPCI85 Central Processing/Communication and SICORE Base system. The vulnerability class involves a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. Likely operational impact includes compromised system integrity and unauthorized access to critical system functions. Source-confidence li [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-09T00:00:00.000Z and has not been modified since then. The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. Organizations s [truncated]
Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user. The vulnerability can be exploited if an attacker tricks a user into opening and running a s [truncated]
CVE-2025-31115 is a high-severity flaw in XZ Utils’ liblzma multithreaded .xz decoder. The supplied Siemens advisory maps the issue to specific SIMATIC S7-1500 CPU variants and states that invalid input can trigger a crash, heap use-after-free, or a write based on a null pointer plus offset. Siemens’ advisory says no fix is currently available for the listed products, so operators should rely on compensat [truncated]
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resu [truncated]
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gainin [truncated]
A path traversal vulnerability was identified in Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The issue arises from improper sanitization of path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows an attacker to access unintended file system locations through crafted input.
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary com [truncated]
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key mater [truncated]
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), [truncated]
CVE-2025-66382 is a low-severity availability issue in libexpat that Siemens mapped to several SIMATIC S7-1500 CPU 1518 MFP/F MFP and SIPLUS variants. A crafted file of roughly 2 MiB can make processing take dozens of seconds, creating a denial-of-service-style slowdown rather than a confidentiality or integrity impact. CISA’s advisory lists no fix at the time of the source publication and recommends rest [truncated]
A NULL pointer dereference vulnerability exists in OpenSSL's PKCS12_item_decrypt_d2i_ex() function when processing malformed PKCS#12 files. The function fails to validate whether the oct parameter is NULL before dereferencing it. When PKCS12_unpack_p7encdata() passes a malformed PKCS#12 file, this parameter can be NULL, resulting in a crash. The vulnerability is confined to Denial of Service and cannot be [truncated]
CVE-2025-40833 is a high-severity denial-of-service issue in affected Siemens industrial devices. The advisory says specially crafted IPv4 requests can trigger a null pointer dereference, and recovery requires a manual restart. The CVE was published on 2026-05-12 and modified on 2026-05-14. Because the issue is network reachable and requires no privileges or user interaction, operators should treat expose [truncated]
CVE-2026-44412 is a high-severity memory corruption issue in Siemens Solid Edge affecting versions earlier than V226.0 Update 5. A specially crafted PAR file can trigger a stack-based overflow and may lead to code execution in the context of the current process.
CVE-2026-44411 is a high-severity Siemens Solid Edge issue where parsing specially crafted PAR files can trigger uninitialized pointer access. CISA’s advisory describes the impact as potential code execution in the context of the current process. Siemens’ remediation is to update to V226.0 Update 5 or later.
CVE-2026-41551 is a critical path traversal issue in Siemens ROS# versions before 2.2.2. CISA’s advisory says unsanitized user input can let a remote attacker access arbitrary files on the device. The advisory was first published on 2026-05-12 and republished on 2026-05-14 to incorporate Siemens ProductCERT’s SSA-357982 notice.
CVE-2026-33893 is a high-severity Siemens Teamcenter issue in which a hardcoded obfuscation key is stored directly in the application. If an attacker extracts that key, it could be reused to gain unauthorized access. The advisory was published on 2026-05-12 and republished by CISA on 2026-05-14, with vendor fixes listed for affected Teamcenter branches.
CVE-2026-33862 is a high-severity cross-site scripting issue in Siemens Teamcenter. The advisory says the affected application does not properly encode or filter user-supplied data, which can let an attacker inject malicious code that executes when other users visit the affected page. CISA published the advisory on 2026-05-12 and republished Siemens ProductCERT guidance on 2026-05-14.
CVE-2026-31790 is a high-severity information-disclosure issue described in the CISA-republished Siemens advisory. The flaw can cause an application using RSASVE key encapsulation to return success even when RSA encryption fails, leaving the caller to use an output buffer that may contain stale or uninitialized data. If that buffer is sent to a peer, sensitive data from prior process execution may be exposed.
CVE-2026-31789 is a heap buffer overflow in OpenSSL’s handling of very large X.509 OCTET STRING values when converting them to hexadecimal strings. The issue was published on 2026-04-07. It is triggered only on 32-bit platforms when buffer sizing multiplies the input length by 3 and overflows, resulting in allocation of a buffer that is too small. The vendor notes that exploitation would require crafted c [truncated]
CVE-2026-28390 is a denial-of-service vulnerability in CMS message processing: a crafted CMS EnvelopedData message using KeyTransportRecipientInfo and RSA-OAEP can trigger a NULL pointer dereference when the optional parameters field is missing. The advisory says applications that call CMS_decrypt() on attacker-controlled input may crash before authentication or cryptographic operations complete. CISA’s r [truncated]