These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-39682 describes a Linux kernel TLS receive-path bug that is triggered by a corner case involving zero-length records already queued on rx_list. The advisory text says recvmsg() is supposed to process contiguous DATA records or a single non-DATA record, and that record-type changes should stop the loop. The fix addresses the case where the first record comes from rx_list and is zero-length. In the [truncated]
A vulnerability in WTV676-HB6035 Web Interface and WTV776-HB6035 Web Interface could allow an unauthenticated remote attacker to force the device into protection mode, losing remote connectivity functions. This issue arises from improper input validation received from backend services, which could lead to a loss of remote connectivity functions. Defenders should assess exposure and prioritize verification [truncated]
CVE-2025-25249 is described in the supplied corpus as a high-severity, network-reachable heap-based buffer overflow that could allow unauthorized code or command execution via specially crafted packets. The advisory should be treated as important, but the source data contains a material scope mismatch: the CISA CSAF product tree names Siemens RUGGEDCOM APE1808, while the vulnerability text and remediation [truncated]
A vulnerability in SIMOVE Fleetmanager and SIPLANT products allows unauthenticated remote attackers to read arbitrary files from the underlying operating system, potentially exposing sensitive data. The affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This vulnerability could allow attackers to access sensitive [truncated]
A vulnerability in Reyrolle 7SR5 devices allows for the execution of arbitrary, unsigned code during a special maintenance mode activated via a physical key sequence. This mode enables the device to download and execute program code from a network server without verifying its authenticity or integrity. An attacker with physical access could exploit this to upload and execute malicious code.
A vulnerability in Reyrolle 7SR5 devices could allow an unauthenticated attacker with physical access to cause a crash and potentially execute arbitrary code. This is due to improper validation of input received over a proprietary communication protocol when the device is in a special firmware-update mode, leading to a memory corruption condition. Defenders should prioritize assessing physical security, v [truncated]
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
A vulnerability in Reyrolle 7SR5 (All versions < V2.70) allows an authenticated, low-privileged remote attacker to escalate privileges to an administrative level by bypassing role-based access control (RBAC) restrictions through manipulation of request data. This vulnerability could allow for unauthorized administrative access, potentially leading to further exploitation and lateral movement within affect [truncated]
A vulnerability in Reyrolle 7SR5 (All versions < V2.70) allows an unauthenticated remote attacker to cause a denial-of-service condition by crashing and rebooting the device due to improper management of system resources when processing concurrent HTTP requests. This issue affects device availability and reliability, emphasizing the need for defenders to assess exposure and prioritize verification of devi [truncated]
A vulnerability in Reyrolle 7SR5 (All versions < V2.70) allows an unauthenticated remote attacker to cause a denial-of-service condition by crashing the device, resulting in a reboot. The vulnerability is caused by improper validation of the URL component in pre-authenticated HTTP messages, leading to an out-of-bounds write condition in memory. Defenders should assess exposure and potential impact of deni [truncated]
A vulnerability in Reyrolle 7SR5 devices could allow an unauthenticated remote attacker to predict generated security-relevant values, potentially gaining unauthorized access. This critical vulnerability affects devices with versions prior to V2.70 and could enable attackers to impersonate legitimate authenticated users, leading to unauthorized access and potential disruptions to device operations. Defend [truncated]
A vulnerability in Reyrolle 7SR5 (All versions < V2.70) generates session identifiers using an algorithm with insufficient randomness, allowing an unauthenticated remote attacker to derive valid session identifiers and bypass authentication. This issue has significant implications for system security, particularly for remote access and authentication mechanisms. Defenders should assess exposure, verify ve [truncated]
A vulnerability in Reyrolle 7SR5 (All versions < V2.70) exposes information through the web interface that can be used to calculate session ID numbers, potentially allowing unauthorized access. This critical vulnerability requires defenders to verify exposure and apply patches or mitigations to prevent bypassing authentication and gaining unauthorized access to the device. The vulnerability's impact inclu [truncated]
A vulnerability in Teamcenter allows an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user, enabling actions within the victim's Teamcenter session. This could lead to unauthorized actions, data tampering, or exposure. Defenders should prioritize patching, monitoring, and input validation. The vulnerability affects Teamcenter V2412, V2506, V2512, and V [truncated]
A vulnerability in Siveillance Control Pro and Siveillance Control products allows arbitrary file uploads through the OIS web module, potentially leading to full compromise of the affected environment. This could result in root access on host systems. Defenders managing these systems should prioritize inventory checks, version verification, and patch application to prevent potential full compromise. The v [truncated]
A vulnerability in Desigo CC ClickOnce Client and other related products allows for Client Code Execution (CCE) due to insufficient input validation of scripts in user-defined graphics documents. An attacker could exploit this by crafting a malicious document to execute arbitrary files on a client's operating system, potentially leading to system compromise and lateral movement.
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
A low-severity vulnerability was found in kas, a setup tool for bitbake based projects. The issue allows an attacker to increase the risk of a man-in-the-middle attack by compromising session confidentiality or integrity due to a misconfigured SSH setting. This vulnerability affects systems using kas versions prior to 5.4. Defenders should assess exposure and prioritize verification and remediation effort [truncated]
A setup tool for bitbake based projects, kas, processes repositories prior to validating signatures under specific conditions, allowing potential replacement of original repositories with attacker-controlled ones. This vulnerability, present in versions 4.8 and prior to 5.3, can be exploited if an attacker has control of a repository referenced by a kas file, and specific configurations are in place, such [truncated]
kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an [truncated]
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. The vulnerability, tracked as CVE-2026-69109, has a CVSS score of 8.7, indicating a high severity level. Organizations u [truncated]
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise. The vulnerability exists in Siemens License Server (SLS) versions prior to V5.1 an [truncated]
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contain an out-of-bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. Organizations using Simcenter Femap, especially versions prior to V2606.0001, should be aware of this vulnerability and take ne [truncated]
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) v [truncated]
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to cr [truncated]
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash. The vulnerability affects LOGO! Soft Comfort versions prior to V9. Siemen [truncated]
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process. Organizations should review PAR file handling and validate input so [truncated]
A use-after-free vulnerability was identified in Solid Edge SE2025 and SE2026, which could allow an attacker to execute code in the context of the current process by parsing specially crafted DFT files. The vulnerability has a high CVSS score of 7.3 and is considered a high priority due to the potential for code execution. Affected product context and defensive impact should be considered when assessing t [truncated]
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. The vulnerability is an out of bounds write issue in Solid Edge SE [truncated]