PatchSiren

siemens CVE debriefs · Page 13

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-12-09

CVE-2025-40807

A capture-replay vulnerability in Siemens Gridscale X Prepay allows an authenticated but locked-out user to re-establish valid sessions by replaying previously captured authentication tokens. The flaw stems from insufficient token invalidation upon account lockout, enabling session resurrection without fresh authentication. With a CVSS 6.3 (Medium), this poses moderate risk in operational technology envir [truncated]

HIGH Siemens CVE published 2025-12-09

CVE-2025-40801

CVE-2025-40801 affects Siemens COMOS and is caused by the SALT SDK not validating the server certificate when establishing TLS connections to the authorization server. In the supplied advisory data, that weakness could allow a man-in-the-middle attack against affected connections. Siemens recommends updating to V10.6.1 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2025-40800

CVE-2025-40800 affects Siemens COMOS, where the IAM client does not validate the server certificate when establishing TLS connections to the authorization server. That weakness can let an attacker in the network path perform a man-in-the-middle attack against authentication traffic. CISA’s CSAF republication identifies affected COMOS product lines and points to Siemens’ remediation: update to V10.6.1 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2024-56840

CVE-2024-56840 is a Siemens RUGGEDCOM ROX II family vulnerability involving IPsec under certain conditions. The advisory says the issue may allow code injection on the affected device, and an attacker could leverage it to execute arbitrary code as root. CISA’s CSAF entry lists the issue as high severity with CVSS 3.1 score 7.2, and Siemens provides a fixed version: V2.17.0 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2024-56839

CVE-2024-56839 affects Siemens RUGGEDCOM ROX II family devices when VRF (Virtual Routing and Forwarding) is in use. According to the supplied advisory text, an attacker could leverage this condition to achieve code injection and execute arbitrary code as root. The CVE was published on 2025-12-09 and is rated HIGH with CVSS 7.2.

HIGH Siemens CVE published 2025-12-09

CVE-2024-56838

CVE-2024-56838 affects Siemens RUGGEDCOM ROX II family devices through a SCEP client flaw in secure certificate enrollment. According to the CISA CSAF advisory, the client lacks validation of multiple fields, and an attacker could leverage that weakness to execute arbitrary code as the root user. Siemens lists an update to V2.17.0 or later as the remediation, and the issue is not marked as a CISA KEV incl [truncated]

HIGH Siemens CVE published 2025-12-09

CVE-2024-56837

Siemens RUGGEDCOM ROX II family is affected by an insufficient-validation issue during installation and loading of certain configuration files. According to the supplied advisory text, an attacker could use this weakness to spawn a reverse shell and gain root access on the affected system. The vendor remediation is to update to V2.17.0 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2024-56836

CVE-2024-56836 affects Siemens RUGGEDCOM ROX II family devices and is described in the official CISA CSAF advisory and Siemens ProductCERT notice. The issue involves injection of additional configuration parameters during Dynamic DNS configuration; under certain circumstances, an attacker could leverage it to spawn a reverse shell and gain root access. Siemens’ documented remediation is to update to V2.17.0 or later.

HIGH Siemens CVE published 2025-12-09

CVE-2024-56835

CVE-2024-56835 is a high-severity code-injection vulnerability in the DHCP Server configuration file of Siemens RUGGEDCOM ROX II family products. According to the advisory, an attacker could leverage the flaw to spawn a reverse shell and gain root access on the affected system. Siemens and CISA list a vendor fix: update to V2.17.0 or later.

CRITICAL Siemens CVE published 2025-12-09

CVE-2024-47875

CVE-2024-47875 is a critical issue published by CISA for Siemens COMOS, with the advisory description pointing to a DOMPurify nesting-based mXSS weakness. The source record ties the issue to Siemens COMOS V10.4, V10.4.5, V10.5, and V10.6 product lines, and lists fixed releases that should be deployed as soon as practical. Because the CVSS vector is network-reachable and requires no privileges or user inte [truncated]

HIGH Siemens CVE published 2025-11-13

CVE-2024-48510

CVE-2024-48510 is a critical directory traversal vulnerability associated with Siemens SiPass integrated V2.90 and V2.95. According to the advisory, the issue can lead to arbitrary code execution in a restore scenario that uses a specially crafted backup set. Siemens and CISA also note an important constraint: the affected product versions are no longer supported by the maintainer, which narrows the pract [truncated]

HIGH Siemens CVE published 2025-11-11

CVE-2025-40827

CVE-2025-40827 is a high-severity DLL hijacking vulnerability disclosed on 2025-11-11 in CISA’s ICS advisory ICSA-25-317-17. The advisory states that an attacker could execute arbitrary code by placing a crafted DLL file on the system. Siemens lists vendor updates for the affected products as the remediation path.

MEDIUM Siemens CVE published 2025-10-14

CVE-2025-25252

CVE-2025-25252 was publicly disclosed in a CISA CSAF advisory on 2025-02-11 and carries a CVSS 3.1 score of 4.8 (MEDIUM). The source record describes an insufficient session expiration issue that could let a remote attacker reuse a SAML record to access or reopen a terminated session. Because the supplied corpus also contains a product/description mismatch, teams should verify the Siemens advisory and the [truncated]

MEDIUM Siemens CVE published 2025-10-14

CVE-2025-40774

CVE-2025-40774 affects Siemens SiPass integrated server applications. According to CISA and Siemens advisories, user passwords are stored in encrypted form in the database, but the decryption keys are accessible to users with administrative privileges. That design lets an administrator recover valid passwords, which can enable unauthorized account access, data exposure, and broader compromise if those cre [truncated]

LOW Siemens CVE published 2025-10-14

CVE-2025-40773

CVE-2025-40773 affects Siemens SiPass integrated server applications and stems from insufficient server-side authorization checks. In the supplied advisory material, successful abuse could allow an attacker to execute specific API requests and manipulate data belonging to other users. The issue was published by CISA on 2025-10-14 and later republished on 2026-02-12 based on Siemens ProductCERT SSA-599451; [truncated]

HIGH Siemens CVE published 2025-10-14

CVE-2025-40772

CVE-2025-40772 is a stored cross-site scripting (XSS) issue in Siemens SiPass integrated server applications. According to the advisory text supplied in the source corpus, successful exploitation can let an attacker execute malicious code in another user’s browser, impersonate users inside the application, and steal session data. Siemens/CISA assign the issue a CVSS 3.1 score of 7.4 (HIGH).

CRITICAL Siemens CVE published 2025-10-14

CVE-2025-40765

CVE-2025-40765 is a critical information disclosure vulnerability in Siemens TeleControl Server Basic V3.1. According to the CISA CSAF advisory and the Siemens product security advisory, an unauthenticated remote attacker could obtain user password hashes and then use them to log in and perform authenticated operations of the database service. Because the issue is network-reachable, requires no user inter [truncated]

HIGH Siemens CVE published 2025-09-16

CVE-2021-41990

CISA published advisory ICSA-25-259-03 for CVE-2021-41990 on 2025-09-16. The supplied advisory text says the issue is a remote integer overflow in strongSwan’s gmp plugin before version 5.9.4, reachable via a crafted certificate with an RSASSA-PSS signature. Siemens’ affected-product list spans SIMATIC NET, SINEMA Remote Connect Server, SCALANCE, RUGGEDCOM, and related devices. The stated impact is availa [truncated]

HIGH Siemens CVE published 2025-09-12

CVE-2025-9086

CVE-2025-9086 is a high-severity curl cookie handling flaw described in Siemens and CISA advisories. Under a specific secure-cookie-to-cleartext transition, curl can read past a heap buffer boundary while comparing cookie paths. The supplied advisory text says the result can be a crash or an incorrect comparison outcome, and the issue is rated with a CVSS 3.1 score of 7.5 because it can disrupt availability.

MEDIUM Siemens CVE published 2025-09-12

CVE-2025-10148

CVE-2025-10148 is described as a network-reachable flaw that can let a malicious server influence traffic in a way a configured or transparent proxy may misinterpret as legitimate HTTP content, creating cache-poisoning risk. In the supplied source corpus, Siemens ties the advisory to COMOS versions V10.4, V10.4.5, V10.5, and V10.6 and recommends updating to V10.6.1 or later, but the vulnerability text its [truncated]

MEDIUM Siemens CVE published 2025-09-09

CVE-2025-40594

A privilege escalation vulnerability in Siemens SINAMICS industrial drives allows unauthorized factory reset execution and configuration manipulation due to improper privilege management and leaked session privileges. The flaw affects SINAMICS G220 V6.4, S200 V6.4, and S210 V6.4 drive systems commonly deployed in manufacturing and critical infrastructure environments. An attacker with local access can exp [truncated]

CRITICAL Siemens CVE published 2025-08-28

CVE-2024-58240

The supplied advisory for CVE-2024-58240 describes a Linux kernel TLS change that separates no-async decryption handling from async handling, with a stated goal of simplifying completion handling and reducing future fix complexity. The source assigns CVSS 3.1 7.3 (HIGH) and recommends updating to V5.0 or later where applicable. However, the supplied metadata maps the issue to Siemens SIMATIC CN 4100 with [truncated]

HIGH Siemens CVE published 2025-08-26

CVE-2023-6378

A serialization vulnerability in the logback receiver component (version 1.4.11) allows remote attackers to cause a Denial-of-Service condition by sending crafted data. The vulnerability affects Siemens SINEC NMS, an industrial network management system. With a CVSS 3.1 score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity, requiring no privileges or user interaction. T [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2025-30033

A DLL hijacking vulnerability in Siemens' setup components allows arbitrary code execution during application installation. The vulnerability affects 80+ Siemens industrial software products using the affected setup component. With a CVSS 3.1 score of 7.8 (HIGH), this local attack vector requires user interaction but grants high impact on confidentiality, integrity, and availability. The vulnerability was [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2025-40890

A stored cross-site scripting (XSS) vulnerability exists in the Dashboards functionality of Siemens RUGGEDCOM APE1808. An authenticated low-privilege user can craft a malicious dashboard containing JavaScript and share it with victims, or socially engineer victims to import a malicious dashboard template. When viewed or imported, the payload executes in the victim's browser context, enabling unauthorized [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2025-40889

A path traversal vulnerability in the Time Machine functionality of Siemens RUGGEDCOM APE1808 allows authenticated users with limited privileges to manipulate files in the /data folder through crafted requests. The vulnerability stems from missing validation of two input parameters. Published on 2025-08-12 and last modified on 2026-01-14, this issue carries a HIGH severity CVSS 3.1 score of 8.1. The vulne [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2025-40888

A SQL injection vulnerability exists in the CLI functionality of Siemens RUGGEDCOM APE1808. An authenticated attacker with limited privileges can execute arbitrary SELECT statements against the backend database, potentially exposing unauthorized data. The vulnerability stems from improper input validation on a CLI parameter. CVSS 3.1 score is 5.3 (Medium), with network attack vector, high attack complexit [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2025-40887

A SQL injection vulnerability in the Alert functionality of Siemens RUGGEDCOM APE1808 allows authenticated users with limited privileges to execute arbitrary SELECT statements against the application's database, potentially exposing unauthorized data. The vulnerability stems from improper input validation on an Alert-related parameter. This is a network-accessible vulnerability requiring low privileges bu [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2025-40886

A SQL injection vulnerability exists in the Alert functionality of Siemens RUGGEDCOM APE1808. An authenticated attacker with limited privileges can execute arbitrary SQL statements against the backend database, potentially leading to unauthorized data exposure, data modification, or availability impacts. The vulnerability stems from improper input validation on an Alert-related parameter. This issue was d [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2025-40885

A SQL injection vulnerability in the Smart Polling functionality of Siemens RUGGEDCOM APE1808 allows authenticated users with limited privileges to execute arbitrary SELECT statements against the application's database. The vulnerability stems from improper input validation on a parameter within the Smart Polling feature. This is a read-only SQL injection—attackers can extract unauthorized data but cannot [truncated]