PatchSiren

siemens CVE debriefs · Page 34

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2025-08-12

CVE-2023-52810

This CVE addresses a vulnerability in the Linux kernel's Journaled File System (JFS) implementation. The issue involved a missing validation check for negative values of the `db_l2nbperpage` parameter, which could lead to undefined behavior or system instability. The vulnerability was resolved by adding an explicit check to prevent negative values from being processed. Siemens has identified this CVE as a [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52809

A NULL pointer dereference vulnerability in the Linux kernel's libfc SCSI subsystem, specifically in fc_lport_ptp_setup(), was resolved in upstream Linux. The vulnerability affects Siemens industrial networking products running SINEC OS, including RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA republished this advisory on 2026-02-25 based on Siemens ProductCERT SSA-613116. The advisory's threat a [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52806

A null pointer dereference vulnerability in the Linux kernel's ALSA HDA (High Definition Audio) subsystem could allow an attacker to cause a denial of service condition. The vulnerability occurs when assigning a stream, where a null pointer may be dereferenced without proper validation. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, includin [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52805

CVE-2023-52805 is a vulnerability in the Linux kernel's JFS (Journaled File System) that was resolved with a fix for an array-index-out-of-bounds condition in the diAlloc function. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting its RUGGEDCOM RST2428P (6GK6242-6PA00) product, as documented in CISA advisory ICSA-25-226-15. The sour [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52804

This CVE addresses a vulnerability in the Linux kernel's Journaled File System (JFS) implementation. The issue involves missing validity checks for the `db_maxag` and `db_agpref` fields, which could lead to improper handling of allocation group parameters. The vulnerability was resolved by adding appropriate validation checks to ensure these values remain within expected bounds. Siemens has identified thi [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52799

CVE-2023-52799 is an array-index-out-of-bounds vulnerability in the Linux kernel's JFS (Journaled File System) implementation, specifically within the `dbFindLeaf` function. The vulnerability was resolved in the upstream Linux kernel. Siemens has identified this CVE as affecting certain industrial networking products, including the RUGGEDCOM RST2428P and SCALANCE X-family switches running SINEC OS. The CI [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52796

This CVE addresses a vulnerability in the Linux kernel's ipvlan networking subsystem. The fix introduces a new helper function `ipvlan_route_v6_outbound()` to properly handle IPv6 outbound routing in ipvlan configurations. The vulnerability was resolved through kernel patch implementation. Siemens has identified this CVE as applicable to certain industrial networking products running SINEC OS, specificall [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52791

A vulnerability in the Linux kernel's I2C subsystem could cause system instability or crashes when I2C transfers are attempted in non-preemptible contexts. The issue stems from the I2C core not properly handling atomic transfers when preemption is disabled, potentially leading to scheduling violations or deadlocks. Siemens has identified this vulnerability as affecting certain industrial networking produc [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52789

A missing null-pointer check for kstrdup() in the Linux kernel's tty vcc driver could allow memory exhaustion or denial-of-service conditions. The vulnerability exists in the vcc_probe() function where the return value of kstrdup() was not validated before use. Siemens has identified this issue as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALA [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52784

A vulnerability in the Linux kernel's bonding driver was resolved by ensuring the device is properly stopped during bond_setup_by_slave() operations. The issue was addressed in the kernel bonding subsystem to prevent potential instability or undefined behavior when configuring bonded network interfaces. Siemens has assessed this vulnerability as affecting certain industrial networking products running SIN [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52774

A race condition vulnerability in the Linux kernel's s390 DASD (Direct Access Storage Device) driver, where concurrent access to the device queue was not properly protected. The vulnerability was resolved by adding proper synchronization mechanisms to protect the device queue against concurrent access. The issue affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RS [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52764

A shift-out-of-bounds vulnerability in the Linux kernel's gspca/cpia1 camera driver was resolved in the media subsystem. The flaw existed in the set_flicker function where improper shift operations could lead to undefined behavior. Siemens has assessed this vulnerability as affecting certain industrial networking products running SINEC OS, which incorporates the Linux kernel. The vulnerability was initial [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52753

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's AMD display driver (drm/amd/display). The issue involves improper handling of the timing generator object, which could lead to system instability or denial of service conditions when the timing generator is accessed without proper validation. The vulnerability was resolved by adding appropriate NULL checks before dereferenci [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52670

CVE-2023-52670 is a memory leak vulnerability in the Linux kernel's rpmsg virtio driver, specifically affecting the handling of driver_override during device removal. The vulnerability occurs when rpmsg_remove() fails to free the driver_override string, leading to a memory leak condition. This issue was resolved in the Linux kernel by ensuring proper deallocation of driver_override when the rpmsg device i [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52655

This CVE addresses a vulnerability in the Linux kernel's USB aqc111 driver. The fix involves adding a proper packet check for fixup operations to ensure true limit validation. The vulnerability was resolved in the Linux kernel, and Siemens has assessed this as 'Misinformed' impact for their affected industrial networking products, indicating the reported vulnerability does not actually affect these produc [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52637

A use-after-free (UAF) vulnerability exists in the Linux kernel's J1939 Controller Area Network (CAN) protocol implementation. The flaw occurs in the j1939_sk_match_filter function during setsockopt(SO_J1939_FILTER) operations, where improper memory handling can lead to a UAF condition. This vulnerability affects Siemens industrial networking products that incorporate the vulnerable Linux kernel component [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52623

A vulnerability in the Linux kernel's SUNRPC subsystem that triggered suspicious RCU (Read-Copy-Update) usage warnings has been resolved. The issue was addressed in the kernel and affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA published this advisory on August 12, 2025, with subsequent updates through February 2026 [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2023-52622

A vulnerability in the Linux kernel's ext4 filesystem could cause online resizing failures when flexible block groups (flex bg) are oversized. The issue has been resolved in the kernel. Siemens has identified this CVE as applicable to certain industrial networking products running SINEC OS, which incorporates the affected Linux kernel component. CISA published this advisory on August 12, 2025, with subseq [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52619

A vulnerability in the Linux kernel's pstore/ram subsystem could cause system crashes when the number of CPUs is configured to an odd number. The issue has been resolved in the kernel. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA published advisory ICSA-25-226-15 on Augu [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52617

A vulnerability in the Linux kernel's PCI switchtec driver could cause a crash during device release after surprise hot removal. The issue was resolved by fixing the stdev_release() function to properly handle cleanup when a device is unexpectedly removed. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SC [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52615

A vulnerability in the Linux kernel's hardware random number generator (hwrng) core subsystem could allow a page fault deadlock condition when the hwrng device is memory-mapped (mmap-ed). The issue was resolved in the Linux kernel. Siemens has identified this vulnerability as affecting certain industrial networking products including the RUGGEDCOM RST2428P and SCALANCE X family switches running SINEC OS. [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52607

A null-pointer dereference vulnerability in the Linux kernel's PowerPC memory management subsystem, specifically within the `pgtable_cache_add` function, has been identified and resolved. This flaw could potentially lead to system instability or denial of service conditions on affected PowerPC-based systems. The vulnerability was addressed through a kernel patch that corrects the null-pointer dereference [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52606

CVE-2023-52606 is a vulnerability in the Linux kernel's PowerPC architecture vector operations library. The issue involves improper validation of size parameters for vector operations, which could lead to memory safety issues. The vulnerability was resolved by adding proper size validation to the powerpc/lib vector operations code. Siemens has identified this CVE as affecting certain industrial networking [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52604

CVE-2023-52604 is a Linux kernel vulnerability in the JFS (Journaled File System) implementation, specifically an array-index-out-of-bounds issue in the dbAdjTree function detected by UBSAN (Undefined Behavior Sanitizer). The vulnerability has been resolved in the Linux kernel. Siemens has identified this CVE as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52602

A slab-out-of-bounds read vulnerability in the Journaled File System (JFS) dtSearch function of the Linux kernel, affecting Siemens industrial network infrastructure products. The vulnerability was resolved in the upstream Linux kernel. CISA and Siemens published coordinated advisories on August 12, 2025, with subsequent updates through February 25, 2026, to refine affected product listings and remove rej [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52601

CVE-2023-52601 is a vulnerability in the Linux kernel's JFS (Journaled File System) that was resolved with a fix for an array-index-out-of-bounds condition in the dbAdjTree function. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting certain industrial networking products, specifically the RUGGEDCOM RST2428P and SCALANCE X family dev [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52600

A use-after-free (UAF) vulnerability in the Journaled File System (jfs) component of the Linux kernel was resolved via a fix in jfs_evict_inode. The vulnerability affects Siemens industrial networking products that incorporate the vulnerable Linux kernel code. CISA published this advisory on August 12, 2025, with subsequent updates through February 25, 2026, including corrections to affected product listi [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2023-52599

CVE-2023-52599 is a vulnerability in the Linux kernel's JFS (Journaled File System) that was resolved with a fix for an array-index-out-of-bounds condition in the diNewExt function. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting its RUGGEDCOM RST2428P (6GK6242-6PA00) product, along with SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-5 [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52598

This CVE addresses a vulnerability in the Linux kernel's s390/ptrace subsystem where the Floating-Point Control (FPC) register was not being handled correctly during ptrace operations. The vulnerability was resolved by implementing proper handling of the FPC register setting. The issue affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-famil [truncated]

Review Siemens CVE published 2025-08-12

CVE-2023-52597

A vulnerability in the Linux kernel's KVM s390 implementation related to incorrect setting of the Floating-Point Control (FPC) register has been identified in Siemens industrial networking products. The FPC register controls floating-point operations and exception handling on IBM Z (s390x) architecture. Improper handling of this register in a virtualized environment could lead to information disclosure or [truncated]