PatchSiren

siemens CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-66030

CVE-2025-66030 is a medium-severity issue in Siemens SIDIS Prime as published by CISA and Siemens. The advisory describes an integer overflow in node-forge ASN.1 OID processing that can let oversized arcs decode to smaller, trusted OIDs, which may undermine OID-based security checks. Siemens lists version 4.0.800 and later as the fix target.

HIGH Siemens CVE published 2026-03-10

CVE-2025-64756

CVE-2025-64756 is a high-severity command-injection issue in a shell-based filename processing path. When the affected -c/--cmd flow is used, matched filenames are passed to a shell with shell: true; if an attacker can influence filenames, shell metacharacters can trigger arbitrary command execution under the user or CI account’s privileges. The supplied CSAF record ties the CVE to Siemens SIDIS Prime and [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-64718

CVE-2025-64718 is a prototype-pollution issue in js-yaml that Siemens/CISA mapped to SIDIS Prime versions earlier than 4.0.800. In the supplied advisory corpus, the concern is that parsing untrusted YAML can let an attacker alter the prototype of parsed objects via __proto__. Siemens’ remediation is to update SIDIS Prime to 4.0.800 or later. The advisory was published on 2026-03-10 and republished on 2026 [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-64157

The supplied advisory data describes an externally controlled format string issue that could let an authenticated admin execute unauthorized code or commands through a specially crafted configuration. Defensive handling should focus on privilege review, configuration-change controls, and vendor patch validation. Important: the corpus contains a product mismatch—CISA metadata names Siemens RUGGEDCOM APE180 [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-62522

CVE-2025-62522 is a confidentiality issue in the Vite development server on Windows. If an application explicitly exposed the dev server to the network, a request whose URL ended with a trailing backslash could cause files blocked by server.fs.deny to be sent. The advisory rates the issue CVSS 6.5 MEDIUM and limits the practical impact to exposed Windows dev servers; integrity and availability are not des [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-62439

CVE-2025-62439 is a Fortinet FortiOS authorization issue tied to improper verification of the source of a communication channel (CWE-940). According to the supplied advisory text, an authenticated user who understands FSSO policy configurations may be able to use crafted requests to reach protected network resources. The source rates the issue CVSS 4.2 (Medium).

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-61624

CVE-2025-61624 is a CWE-22 path traversal issue described in the supplied advisory text as affecting multiple Fortinet platforms, where an authenticated attacker with an admin profile and at least read-write permissions may be able to write or delete arbitrary files via specific CLI commands. The supplied CISA source was published on 2026-03-10 and updated on 2026-05-14; its revision history shows the CVE [truncated]

HIGH Siemens CVE published 2026-03-10

CVE-2025-58754

CVE-2025-58754 is a denial-of-service issue tied in the advisory corpus to Siemens SIDIS Prime, but the vulnerability text itself describes Axios running on Node.js. When an affected Axios version handles a `data:` URL, it can decode the full payload into memory, ignore the usual size guards, and return a synthetic response. A sufficiently large `data:` URI can therefore trigger unbounded memory growth an [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-58752

CVE-2025-58752 describes a file-serving restriction bypass in Vite that can expose HTML files on the machine even when server.fs controls are set. According to the published advisory text, the issue matters most when the dev server is intentionally exposed to the network and when the app uses the default SPA mode or MPA mode. The advisory also says the preview server can serve HTML files outside the outpu [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-58751

According to the supplied advisory text, CVE-2025-58751 describes a Vite dev-server access-control bypass involving the public directory: when the dev server is explicitly exposed to the network, the project uses the public directory feature, and a symlink exists in that directory, files could be served in a way that bypasses server.fs settings. The source corpus says the issue is fixed in Vite 7.1.5, 7.0 [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-55018

CVE-2025-55018 describes an unauthenticated HTTP request smuggling issue in Fortinet FortiOS that can let an attacker send a specially crafted request through firewall policy handling without it being logged. The advisory rates it CVSS 5.8 (medium) and indicates the main concern is improper request interpretation rather than code execution or service outage. The supplied remediation is to update FortiGate [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2025-53847

CVE-2025-53847 is described as a missing-authentication flaw in a critical function that can let an attacker execute unauthorized code or commands using specially crafted packets. The source record is inconsistent about the affected product, so defenders should verify applicability against the official advisory links before assuming impact.

CRITICAL Siemens CVE published 2026-03-10

CVE-2025-40943

CVE-2025-40943 is a critical trace-file sanitization issue affecting multiple Siemens SIMATIC controller families. CISA’s advisory says an attacker can socially engineer an authorized user with the "Read diagnostics" right to import a specially crafted trace file, which may execute code in the client browser session and trigger PLC operations the user is already permitted to perform.

LOW Siemens CVE published 2026-03-10

CVE-2025-27769

CVE-2025-27769 affects Siemens Heliox EV charging stations and is rated LOW with a 2.6 CVSS score. The issue is an improper access control weakness that could let an attacker reach unauthorized services through the charging cable.

HIGH Siemens CVE published 2026-03-10

CVE-2025-15284

CVE-2025-15284 is a denial-of-service issue published by CISA on 2026-03-10 and republished on 2026-03-12 in Siemens advisory content. The source corpus says the underlying problem is improper input validation in qs parsing: bracket notation can bypass arrayLimit enforcement, allowing unbounded array growth and memory exhaustion.

HIGH Siemens CVE published 2026-03-10

CVE-2025-12816

CVE-2025-12816 is a high-severity interpretation-conflict issue tied to Siemens SIDIS Prime, with CISA and Siemens advising remediation for affected versions earlier than 4.0.800. The advisory says crafted ASN.1 structures can desynchronize schema validation and create semantic divergence, which may affect downstream cryptographic verification and security decisions.

HIGH Siemens CVE published 2026-03-10

CVE-2024-30172

CVE-2024-30172 is a high-severity availability issue tied to Siemens SIDIS Prime’s advisory trail and a Bouncy Castle Java Cryptography API weakness. The source advisory states that a crafted Ed25519 signature and public key can trigger an infinite loop in verification code in Bouncy Castle versions before 1.78. Siemens maps the affected product exposure to SIDIS Prime versions before V4.0.800 and recomme [truncated]

MEDIUM Siemens CVE published 2026-03-10

CVE-2024-30171

CISA’s Siemens SIDIS Prime advisory for CVE-2024-30171 describes a timing-based leakage issue in the Bouncy Castle Java TLS API and JSSE Provider before 1.78. The concern is exception-processing timing during RSA-based handshakes, and Siemens maps remediation to SIDIS Prime V4.0.800 or later.

HIGH Siemens CVE published 2026-03-10

CVE-2024-29857

CVE-2024-29857 is a high-severity availability issue affecting Siemens SIDIS Prime versions before 4.0.800. According to the CISA/Siemens advisory chain, importing an EC certificate with crafted F2m parameters can drive excessive CPU consumption while curve parameters are evaluated. The vendor remediation is to update to V4.0.800 or later.

CRITICAL Siemens CVE published 2026-03-04

CVE-2026-27446

CVE-2026-27446 is a missing-authentication issue in Apache Artemis / Apache ActiveMQ Artemis that can let an unauthenticated remote attacker use the Core protocol to make a target broker open an outbound federation connection to an attacker-controlled rogue broker. In vulnerable deployments, that can lead to message injection into queues and/or message exfiltration through the rogue broker. The advisory s [truncated]

HIGH Siemens CVE published 2026-02-18

CVE-2023-7104

CISA’s ICS advisory ICSA-25-100-02, based on Siemens ProductCERT advisory SSA-277137, maps CVE-2023-7104 to Siemens SIDIS Prime. The advisory describes a heap-based buffer overflow in SQLite’s sessionReadRecord path (ext/session/sqlite3session.c) and recommends updating SIDIS Prime to V4.0.700 or later. The source advisory was published on 2025-04-08 and revised on 2025-05-06 for typo fixes.

HIGH Siemens CVE published 2026-02-10

CVE-2026-25656

CVE-2026-25656 is a high-severity local privilege-escalation issue affecting Siemens SINEC NMS and the User Management Component (UMC). According to the CISA-republished Siemens advisory, a low-privileged user can improperly modify a configuration file, which may allow malicious DLL loading and potentially lead to arbitrary code execution with SYSTEM privileges. Siemens has issued fixed versions for the a [truncated]

HIGH Siemens CVE published 2026-02-10

CVE-2026-25655

CVE-2026-25655 affects Siemens SINEC NMS and the User Management Component (UMC). A low-privileged user may be able to improperly modify a configuration file, creating a path to load malicious DLLs and potentially execute code with administrative privilege. Siemens and CISA advise upgrading to V4.0 SP2 or later.

HIGH Siemens CVE published 2026-02-10

CVE-2026-23720

CVE-2026-23720 is a high-severity vulnerability in Siemens Simcenter Femap and Simcenter Nastran. According to the advisory, specially crafted NDB files can trigger an out-of-bounds read during parsing, which could allow code execution in the context of the current process. Siemens and CISA both list vendor fixes for affected products, and the advisory also recommends avoiding untrusted NDB files.

HIGH Siemens CVE published 2026-02-10

CVE-2026-23719

CVE-2026-23719 is a high-severity heap-based buffer overflow affecting Siemens Simcenter Femap and Simcenter Nastran when parsing specially crafted NDB files. A successful attack could allow code execution in the context of the current process, so organizations should treat any workflow that opens untrusted NDB files as exposed until patched.

HIGH Siemens CVE published 2026-02-10

CVE-2026-23718

CVE-2026-23718 is a high-severity vulnerability in Siemens Simcenter Femap and Simcenter Nastran. A specially crafted NDB file can trigger an out-of-bounds read during parsing, which may allow code execution in the context of the current process. The advisory is publicly available and was republished by CISA with Siemens ProductCERT source data.

HIGH Siemens CVE published 2026-02-10

CVE-2026-23717

CVE-2026-23717 is a high-severity vulnerability in Siemens Simcenter Femap and Simcenter Nastran that can trigger an out-of-bounds read while parsing specially crafted XDB files. The published advisory states this could allow code execution in the context of the current process. The issue was publicly disclosed on 2026-02-10, with a CISA republication of the Siemens ProductCERT advisory on 2026-02-17. No [truncated]

HIGH Siemens CVE published 2026-02-10

CVE-2026-23716

CVE-2026-23716 is a high-severity vulnerability in Siemens Simcenter Femap and Simcenter Nastran. According to the advisory, the affected applications can perform an out-of-bounds read while parsing specially crafted XDB files, which could allow code execution in the context of the current process. The issue was publicly disclosed on 2026-02-10 and later republished by CISA on 2026-02-17 with Siemens Prod [truncated]

HIGH Siemens CVE published 2026-02-10

CVE-2026-23715

CVE-2026-23715 is a high-severity Siemens Simcenter Femap/Nastran issue in XDB parsing. A specially crafted XDB file can trigger an out-of-bounds write and may let an attacker execute code in the context of the current process. The supplied advisory data rates the issue 7.8 HIGH and indicates user interaction is required.

HIGH Siemens CVE published 2026-02-10

CVE-2026-22923

CVE-2026-22923 is a high-severity Siemens NX issue in the PDF export path. CISA’s advisory, republished from Siemens ProductCERT SSA-535115, says a local attacker with privileged access to NX running in managed mode could interfere with internal data during export and potentially cause arbitrary code execution.