PatchSiren

siemens CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2026-08-11

CVE-2026-50058

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. The vulnerability affects Solid Edge SE2025 and SE2026 applications [truncated]

Known exploited Siemens CVE published 2026-07-27

CVE-2025-68686

Based on the advisory metadata and linked vendor/CISA publications, CVE-2025-68686 affects Siemens RUGGEDCOM APE1808 and describes a post-exploitation exposure: a remote unauthenticated attacker may use crafted HTTP requests to bypass a patch intended to address symbolic-link persistency. The source notes say the attacker would first need filesystem-level compromise through another vulnerability, so this [truncated]

CRITICAL Siemens CVE published 2026-07-14

CVE-2026-56451

A critical vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header, allowing an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms, and impersonate any user, including administrative accounts. This could potentially grant full unauthorized access t [truncated]

HIGH Siemens CVE published 2026-07-14

CVE-2026-54429

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application become [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2025-40945

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T10:16:30.783Z and has not been modified since then. A vulnerability in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. The CVSS score is 8.5, indicating high severity. Users of COMOS V10.4.5, COMOS V10.6, Designcenter NX, Simcenter 3D [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2025-21846

CVE-2025-21846 is a MEDIUM severity vulnerability (CVSS 5.5) affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability involves the Linux kernel's process accounting (acct) subsystem, where the last write operation is performed from a workqueue context. This local attack vector vulnerability requires low privileges and no user interaction, with avail [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2025-21814

A vulnerability in the Linux kernel's PTP (Precision Time Protocol) subsystem affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial controllers. The issue stems from a missing validation that the `info->enable` callback is set before invocation, which can lead to a NULL pointer dereference. This local vulnerability requires low privileges to exploit and results in high availability [truncated]

HIGH Siemens CVE published 2026-07-14

CVE-2025-21764

CVE-2025-21764 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's IPv6 Neighbor Discovery (NDISC) subsystem. The issue involves missing RCU (Read-Copy-Update) protection in the ndisc_alloc_skb() function, which can lead to use-after-free conditions. This vulnerability was published on April 9, 2024, and most recently modified on May 14, 2026. Siemens has identified this vulnerability [truncated]

HIGH Siemens CVE published 2026-07-14

CVE-2025-21760

CVE-2025-21760 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's IPv6 Neighbor Discovery (NDISC) subsystem. The issue involves insufficient RCU (Read-Copy-Update) protection in the ndisc_send_skb() function, which can lead to use-after-free conditions. The vulnerability was published on 2024-04-09 and last modified on 2026-05-14. Siemens has identified this vulnerability as affectin [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2025-21648

A vulnerability in the Linux kernel's netfilter connection tracking (conntrack) subsystem allows triggering a WARN_ON_ONCE warning when resizing the conntrack hashtable. The issue occurs because the hashtable size was not clamped to INT_MAX, and __GFP_NOWARN is unset during allocation. When an oversized allocation is attempted via __kvmalloc_node_noprof(), the kernel emits a warning. The vulnerability is [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2024-58058

A NULL pointer dereference vulnerability in the UBIFS (Unsorted Block Image File System) implementation of the Linux kernel. The flaw occurs when the TNC (Tree Node Cache) tree dumping routine fails to validate that the zroot pointer is non-NULL before dereferencing it. This can lead to a kernel crash (denial of service) when triggered by a local attacker with low privileges. The vulnerability affects Sie [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2024-58020

CVE-2024-58020 is a NULL pointer dereference vulnerability in the Linux kernel's HID multitouch driver, specifically in the `mt_input_configured` function. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The flaw occurs when the multitouch input configuration fails to validate a pointer before derefe [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2024-58016

CVE-2024-58016 is a medium-severity vulnerability (CVSS 5.5) affecting the SafeSetID Linux Security Module (LSM), specifically impacting the GNU/Linux subsystem within Siemens SIMATIC S7-1500 TM MFP industrial control systems. The vulnerability stems from insufficient validation of policy write sizes in the safesetid module, which could allow local attackers to cause denial-of-service conditions. Publishe [truncated]

HIGH Siemens CVE published 2026-07-14

CVE-2024-57979

A use-after-free vulnerability in the Pulse Per Second (PPS) subsystem of the Linux kernel affects the GNU/Linux subsystem embedded in Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw, published 2024-04-09, allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impact without user interaction. The vulnerability stems from improper memory man [truncated]

HIGH Siemens CVE published 2026-07-14

CVE-2024-56631

A use-after-free vulnerability in the Linux kernel's SCSI generic (sg) driver affects Siemens SIMATIC S7-1500 TM MFP industrial control systems. The flaw resides in sg_release(), where improper sequencing of resource cleanup and mutex operations can lead to slab-use-after-free conditions. Discovered by syzbot with KASAN detection, this vulnerability allows a local attacker with low privileges to potential [truncated]

MEDIUM Siemens CVE published 2026-07-14

CVE-2024-53124

CISA’s advisory for CVE-2024-53124 associates the issue with Siemens SIMATIC S7-1500 TM MFP - BIOS and rates it MEDIUM (CVSS 4.7). The advisory states that no fix is currently available and recommends a workaround focused on trusted software sources. Based on the CVSS vector, the issue requires local access with low privileges, is high complexity, needs no user interaction, and primarily affects availability.

CRITICAL Siemens CVE published 2026-07-14

CVE-2023-45853

CVE-2023-45853 is a critical memory-corruption flaw tied to MiniZip in zlib through 1.3 and mapped by Siemens to multiple SCALANCE WAB/WAM/WUB/WUM devices. The issue is described as an integer overflow that can lead to a heap-based buffer overflow in zipOpenNewFileInZip4_64 when processing a long filename, comment, or extra field. Siemens’ advisory and the CISA CSAF record were published on 2025-02-11 and [truncated]

MEDIUM Siemens CVE published 2026-07-09

CVE-2026-54800

The CVE-2026-54800 vulnerability affects Siemens CPCI85 Central Processing/Communication and SICORE Base system. The vulnerability class involves a default configuration that disables all OPC UA security mechanisms, potentially allowing unauthorized access and control. Likely operational impact includes compromised system integrity and unauthorized access to critical system functions. Source-confidence li [truncated]

MEDIUM Siemens CVE published 2026-07-09

CVE-2026-54798

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-09T00:00:00.000Z and has not been modified since then. The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. Organizations s [truncated]

MEDIUM Siemens CVE published 2026-06-30

CVE-2026-48192

Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user. The vulnerability can be exploited if an attacker tricks a user into opening and running a s [truncated]

HIGH Siemens CVE published 2026-06-09

CVE-2026-46749

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resu [truncated]

HIGH Siemens CVE published 2026-06-09

CVE-2026-46748

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gainin [truncated]

MEDIUM Siemens CVE published 2026-06-09

CVE-2026-46747

A path traversal vulnerability was identified in Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The issue arises from improper sanitization of path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows an attacker to access unintended file system locations through crafted input.

HIGH Siemens CVE published 2026-06-09

CVE-2026-46746

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary com [truncated]

HIGH Siemens CVE published 2026-06-09

CVE-2026-24349

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key mater [truncated]

MEDIUM Siemens CVE published 2026-06-09

CVE-2025-40808

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), [truncated]

MEDIUM Siemens CVE published 2026-05-26

CVE-2025-69421

A NULL pointer dereference vulnerability exists in OpenSSL's PKCS12_item_decrypt_d2i_ex() function when processing malformed PKCS#12 files. The function fails to validate whether the oct parameter is NULL before dereferencing it. When PKCS12_unpack_p7encdata() passes a malformed PKCS#12 file, this parameter can be NULL, resulting in a crash. The vulnerability is confined to Denial of Service and cannot be [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-40833

CVE-2025-40833 is a high-severity denial-of-service issue in affected Siemens industrial devices. The advisory says specially crafted IPv4 requests can trigger a null pointer dereference, and recovery requires a manual restart. The CVE was published on 2026-05-12 and modified on 2026-05-14. Because the issue is network reachable and requires no privileges or user interaction, operators should treat expose [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2026-44412

CVE-2026-44412 is a high-severity memory corruption issue in Siemens Solid Edge affecting versions earlier than V226.0 Update 5. A specially crafted PAR file can trigger a stack-based overflow and may lead to code execution in the context of the current process.

HIGH Siemens CVE published 2026-05-12

CVE-2026-44411

CVE-2026-44411 is a high-severity Siemens Solid Edge issue where parsing specially crafted PAR files can trigger uninitialized pointer access. CISA’s advisory describes the impact as potential code execution in the context of the current process. Siemens’ remediation is to update to V226.0 Update 5 or later.