PatchSiren

siemens CVE debriefs · Page 12

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2026-01-28

CVE-2023-7256

CVE-2023-7256 describes a libpcap ownership-handling flaw that can lead to a double free during remote packet capture setup. In the Siemens advisory republished by CISA, the issue is tied to affected firmware in multiple Siemens industrial product families, including the RUGGEDCOM/SCALANCE context provided here. Siemens recommends updating affected products to V3.3 or later.

MEDIUM Siemens CVE published 2026-01-28

CVE-2023-42366

CVE-2023-42366 is a BusyBox heap-buffer-overflow in awk.c next_token() that Siemens republished for affected OT networking products running SINEC OS firmware. The advisory scope includes RUGGEDCOM RST2428P and multiple SCALANCE families, with remediation directing customers to update to V3.3 or later. The published CVSS vector indicates local attack conditions, no privileges required, user interaction req [truncated]

HIGH Siemens CVE published 2026-01-28

CVE-2023-42365

CVE-2023-42365 is a BusyBox use-after-free issue in awk.c copyvar triggered by a crafted awk pattern. CISA republished Siemens ProductCERT advisory SSA-089022 as ICSA-26-043-06, tying the issue to Siemens SINEC OS firmware used across several industrial networking products and recommending an update to V3.3 or later. The CVSS vector indicates local access with user interaction, but the impact is high if a [truncated]

MEDIUM Siemens CVE published 2026-01-28

CVE-2023-42364

CVE-2023-42364 is a BusyBox use-after-free issue tied to awk pattern handling that can crash affected Siemens industrial devices and cause denial of service. CISA’s CSAF advisory for Siemens was published on 2026-01-28 and updated through 2026-02-25; the cited remediation is to move to V3.3 or later where applicable.

MEDIUM Siemens CVE published 2026-01-28

CVE-2023-42363

CVE-2023-42363 is a use-after-free vulnerability in BusyBox's xasprintf function that Siemens and CISA map to affected Siemens SINEC OS firmware on several industrial networking products, including the RUGGEDCOM RST2428P and multiple SCALANCE families. The supplied advisory rates the issue Medium (CVSS 5.5) and indicates denial-of-service impact as the main consequence.

MEDIUM Siemens CVE published 2026-01-28

CVE-2023-39810

CVE-2023-39810 is a medium-severity Siemens OT issue rooted in BusyBox CPIO handling. On affected SINEC OS firmware, a crafted archive can enable directory traversal, so operators should prioritize the vendor firmware update and review any workflows that process untrusted archives.

HIGH Siemens CVE published 2026-01-28

CVE-2022-48174

CVE-2022-48174 is a high-severity BusyBox shell vulnerability that Siemens republishes for several industrial networking products in its SINEC OS / SCALANCE / RUGGEDCOM portfolio. The source advisory describes a stack overflow in ash.c:6030 in BusyBox before 1.35, with the potential for arbitrary code execution in the affected environment. Siemens’ remediation is to update affected products to V3.3 or later.

MEDIUM Siemens CVE published 2026-01-26

CVE-2025-9820

CVE-2025-9820 describes a stack-based buffer overflow in GnuTLS's gnutls_pkcs11_token_init() routine when processing an unexpectedly long PKCS#11 token label. In the CISA/Siemens advisory, the issue is tied to Siemens SIMATIC CN 4100 versions earlier than 5.0, with Siemens recommending an update to V5.0 or later. The primary documented impact is denial of service via crash, with code execution also descri [truncated]

HIGH Siemens CVE published 2026-01-13

CVE-2025-40944

CVE-2025-40944 is a network-reachable denial-of-service issue affecting multiple Siemens SIMATIC and SIPLUS industrial communication products. A valid S7 protocol Disconnect Request (COTP DR TPDU) sent to TCP port 102 can place affected devices into an improper session state, causing them to become unresponsive until they are power-cycled. CISA’s republication of Siemens ProductCERT guidance lists network [truncated]

HIGH Siemens CVE published 2026-01-13

CVE-2025-40942

CVE-2025-40942 affects Siemens TeleControl Server Basic and is described by CISA as a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges. The advisory reports a CVSS v3.1 score of 8.8 (High) with a local attack vector and elevated impact. Siemens recommends updating to V3.1.2.4 or later.

HIGH Siemens CVE published 2026-01-13

CVE-2025-40899

CVE-2025-40899 is a high-severity stored cross-site scripting issue in the Assets and Nodes functionality. An authenticated user with custom fields privileges can place a malicious custom field that is later rendered in another user's browser, letting the attacker act in the victim's session and potentially modify data, disrupt availability, or view limited sensitive information. The supplied advisory was [truncated]

HIGH Siemens CVE published 2026-01-13

CVE-2025-40898

CVE-2025-40898 affects Siemens RUGGEDCOM APE1808 devices and is rated HIGH (CVSS 8.1). The issue is a path traversal weakness in the Import Arc data archive feature: an authenticated user with limited privileges can upload a specially crafted archive and potentially write arbitrary files to arbitrary paths. In practice, that can alter device configuration and may affect availability.

HIGH Siemens CVE published 2026-01-13

CVE-2025-40897

CVE-2025-40897 is an access control flaw in the Threat Intelligence functionality of Siemens RUGGEDCOM APE1808. An authenticated user with view-only privileges can perform administrative actions, which can alter rules configuration and affect availability. The advisory rates the issue HIGH (CVSS 8.1) and maps it to CWE-863 (incorrect authorization).

MEDIUM Siemens CVE published 2026-01-13

CVE-2025-40894

CVE-2025-40894 is a stored HTML injection issue in the Alerted Nodes Dashboard of Siemens RUGGEDCOM APE1808. An authenticated user with the required privileges can place HTML in a node label; if alerts later render that node in the dashboard, the content may appear in another user’s browser and support phishing or an open redirect scenario. The advisory notes that existing input validation and Content Sec [truncated]

MEDIUM Siemens CVE published 2026-01-13

CVE-2025-40893

CVE-2025-40893 is a stored HTML injection issue in Siemens RUGGEDCOM APE1808 Asset List handling. An unauthenticated attacker can send crafted network traffic that causes HTML tags to be stored in asset attributes. When a user later views affected assets, the injected HTML can render in the browser and may support phishing or open redirect abuse. CISA published the advisory on 2026-01-13 and last updated [truncated]

HIGH Siemens CVE published 2026-01-13

CVE-2025-40892

CVE-2025-40892 is a stored cross-site scripting flaw in the Reports functionality of Siemens RUGGEDCOM APE1808 devices. The issue is caused by improper validation of an input parameter. An attacker with report privileges can store a malicious payload in a report, or a victim can be tricked into importing a malicious report template. When the report is viewed or imported, the script runs in the victim’s br [truncated]

MEDIUM Siemens CVE published 2026-01-13

CVE-2025-40891

CVE-2025-40891 is a medium-severity stored HTML injection issue in the Time Machine Snapshot Diff feature of Siemens RUGGEDCOM APE1808 devices. According to the advisory, an unauthenticated attacker can send specially crafted network packets at two different times so that HTML tags are stored across snapshots. If a victim later opens the specific snapshot diff view and performs the required GUI actions, t [truncated]

CRITICAL Siemens CVE published 2026-01-13

CVE-2025-40805

CVE-2025-40805 is a critical authentication-bypass flaw in Siemens Industrial Edge and related Siemens industrial products. According to CISA’s CSAF republication of Siemens ProductCERT advisory SSA-001536, affected devices do not properly enforce user authentication on specific API endpoints. A remote attacker who already knows the identity of a legitimate user may be able to bypass authentication and im [truncated]

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-59392

A physical-access vulnerability in Elspec G5 devices allows an attacker with physical proximity to reset the administrative password using a USB drive containing a publicly documented reset string. The vulnerability affects devices running firmware through version 1.2.2.19. The CVSS v3.1 vector (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects that while physical presence is required, successful exploitation [truncated]

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40941

CVE-2025-40941 is a medium-severity information disclosure issue affecting Siemens SIMATIC CN 4100. According to the advisory, affected devices may expose server information in responses, which could help an attacker with network access profile the target and increase the likelihood of targeted attacks. Siemens provides a fix in V4.0.1 or later, and the supplied corpus does not indicate KEV listing or kno [truncated]

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40940

CVE-2025-40940 is a Siemens SIMATIC CN 4100 issue described by CISA as inconsistent SNMP behavior across protocol versions, including unexpected service availability and unreliable configuration handling. The reported impact is potential access to sensitive data, which can lead to a confidentiality breach. Siemens' listed remediation is to update to V4.0.1 or later.

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40939

CVE-2025-40939 affects Siemens SIMATIC CN 4100 devices with an exposed USB port that accepts unauthenticated connections. According to the advisory, an attacker with physical access could trigger a reboot and cause a denial-of-service condition. The issue is rated CVSS 4.6 (Medium), and Siemens provides a fixed release: V4.0.1 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2025-40938

CVE-2025-40938 affects Siemens SIMATIC CN 4100. According to the advisory, sensitive information is stored in firmware, which could let an attacker access and misuse it and potentially affect confidentiality, integrity, and availability. Siemens and CISA rate the issue as High severity, and Siemens provides a fixed version.

HIGH Siemens CVE published 2025-12-09

CVE-2025-40937

CVE-2025-40937 affects Siemens SIMATIC CN 4100 and was publicly published on 2025-12-09. According to the CISA CSAF advisory, the application does not properly validate input parameters in its REST API, which can lead to improper handling of unexpected arguments. Siemens and CISA describe the impact as a condition that could allow an authenticated attacker to execute arbitrary code with limited privileges [truncated]

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40935

CVE-2025-40935 is a Siemens RUGGEDCOM vulnerability in the web service TLS certificate upload process. Because the device does not properly validate input, an authenticated remote attacker can trigger a crash and reboot, resulting in a temporary denial of service. Siemens and CISA list remediations in V5.10.1 or later for affected RUGGEDCOM V5.X models.

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40831

CVE-2025-40831 affects Siemens SINEC Security Monitor and is described as a missing input-validation flaw in report generation date handling. An authenticated, low-privileged attacker can trigger a denial-of-service condition in the report functionality. The advisory rates the issue CVSS 6.5 (MEDIUM) and limits the documented impact to availability. Siemens' fix is available in V4.10.0 or later. CISA publ [truncated]

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40830

CVE-2025-40830 affects Siemens SINEC Security Monitor and stems from missing authorization checks in the ssmctl-client file_transfer feature. According to the advisory text, an authenticated local attacker could read or write arbitrary files on the server or sensor. Siemens recommends updating to V4.10.0 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2025-40820

A TCP sequence number validation weakness in Siemens industrial products allows unauthenticated remote attackers to interfere with connection setup, potentially causing denial of service. The attack requires precise timing and the ability to inject spoofed IP packets, limiting practical exploitability but not eliminating risk for exposed TCP-based services.

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40819

CVE-2025-40819 affects Siemens SINEMA Remote Connect Server. According to the CISA/Siemens advisory published on 2025-12-09, affected applications do not properly validate license restrictions against the database. An actor with database access may be able to directly modify the system_ticketinfo table and bypass license limitations without the expected enforcement checks. The published CVSS v3.1 score is [truncated]

LOW Siemens CVE published 2025-12-09

CVE-2025-40818

Siemens SINEMA Remote Connect Server contains private SSL/TLS keys that are not properly protected on the server. An authenticated user with server access may be able to read those keys and potentially impersonate the server, enabling man-in-the-middle attacks, traffic decryption, or unauthorized access to services that trust the affected certificates. CISA classifies the issue as low severity and the sup [truncated]