PatchSiren

siemens CVE debriefs · Page 40

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Siemens CVE published 2025-06-10

CVE-2025-11414

CVE-2025-11414 is tied in Siemens' advisory to the SIMATIC S7-1500 CPU family and an out-of-bounds read in GNU Binutils 2.45. The issue is described as local-only, with a publicly disclosed exploit, and Siemens' advisory states no fix is currently available for the listed products. Near-term defense therefore centers on restricting shell access and using only trusted sources for applications.

LOW Siemens CVE published 2025-06-10

CVE-2025-11413

CVE-2025-11413 is a low-severity memory-safety issue tied in the supplied advisory corpus to Siemens SIMATIC S7-1500 CPU family products that include an additional GNU/Linux subsystem. The underlying bug is described as an out-of-bounds read in GNU Binutils 2.45, and the source notes that a public exploit exists. The upstream Binutils fix is identified as version 2.46 and patch 72efdf166aa0ed72ecc69fc2349 [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-11083

CVE-2025-11083 was published on 2025-06-10 and is mapped in the Siemens/CISA advisory to several SIMATIC S7-1500 CPU 1518 MFP variants. The vulnerability is described as a heap-based buffer overflow in GNU Binutils' elf_swap_shdr path, and the CVE record says the exploit has been publicly disclosed. Siemens’ advisory for the listed products does not show an immediate fix in the supplied source and instead [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2024-6119

CVE-2024-6119 affects multiple Siemens SCALANCE WAB/WAM/WUB/WUM wireless product variants when they perform certificate name checks during TLS client validation. According to the advisory, comparing an expected DNS name, email address, or IP address with an X.509 `otherName` subject alternative name can trigger an invalid memory read and terminate the application process, creating a denial-of-service cond [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-58005

CVE-2024-58005 is a Siemens advisory item for the SIMATIC S7-1500 CPU family that affects several MFP variants. The source advisory describes the issue only briefly, but it assigns a CVSS v3.1 score of 5.5 with a local, low-privilege attack vector and high availability impact. At the time of publication, Siemens reported no fix available, so the immediate defense is to restrict access to the additional GN [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-57996

CVE-2024-57996 is a local denial-of-service issue in the Linux net_sched sch_sfq path that Siemens reported for specific SIMATIC S7-1500 CPU models with an additional GNU/Linux subsystem. The advisory says an incorrectly handled packet limit of 1 can trigger an array-index-out-of-bounds condition and crash when queue length is decremented for an empty slot. Siemens/CISA list no fix as available at publica [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-57924

CVE-2024-57924 is an availability issue in Linux kernel file-handle encoding paths. The fix relaxes incorrect WARN_ON assertions that can fire when filesystem ->encode_fh() fails for legitimate reasons. The supplied advisory corpus associates the CVE with Siemens SIMATIC CN 4100, but the technical description itself is Linux-kernel-specific, so product applicability should be verified against the original [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2024-53166

CVE-2024-53166 is a high-severity use-after-free in the Linux block I/O BFQ scheduler path that Siemens and CISA tied to SIMATIC S7-1500 CPU 1518 MFP variants. The issue is described as a race in bfq_limit_depth() that can dereference a freed bfqq object when an io_context is shared by multiple tasks. Siemens’ advisory states that no fix is currently available and recommends restricting access to the inte [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2024-50246

CVE-2024-50246 was published by CISA on 2025-06-10 as part of Siemens advisory ICSA-25-162-05 / SSA-082556. The source description ties the issue to a Linux kernel fs/ntfs3 attr alloc_size check, while the Siemens advisory scope covers specific SIMATIC S7-1500 CPU family products with an additional GNU/Linux subsystem. At publication, Siemens stated no fix was available and recommended limiting shell acce [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2024-45492

CVE-2024-45492 is a High-severity integer overflow issue in libexpat that Siemens lists in its ICS advisory for the RUGGEDCOM RST2428P and related product families. The flaw is described as occurring in nextScaffoldPart in xmlparse.c before libexpat 2.6.3, and it is specifically noted to affect 32-bit platforms where UINT_MAX equals SIZE_MAX. Siemens recommends updating affected products to V3.1 or later.

CRITICAL Siemens CVE published 2025-06-10

CVE-2024-45490

CVE-2024-45490 is a critical libexpat parsing flaw described by Siemens and CISA for affected industrial products, including RUGGEDCOM RST2428P (6GK6242-6PA00). The advisory states that xmlparse.c does not reject a negative length for XML_ParseBuffer in libexpat versions before 2.6.3. The published CVSS vector is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), so organizations should treat exposed or operation [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-41797

CVE-2024-41797 is a medium-severity authorization flaw in multiple Siemens SCALANCE and RUGGEDCOM devices. According to the advisory, an authenticated remote attacker with the "guest" role could invoke an internal "do system" command beyond their intended privileges. The most notable described impact is the ability to clear the local system log.

HIGH Siemens CVE published 2025-06-10

CVE-2024-37370

CVE-2024-37370 describes an integrity flaw in MIT Kerberos 5 (krb5) before 1.21.3. An attacker can alter the plaintext Extra Count field in a confidential GSS krb5 wrap token, which can make the unwrapped token appear truncated to the application. Siemens’ advisory maps this CVE to several SIMATIC S7-1500 CPU family products and states that no fix is currently available, so affected deployments should rel [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-34397

CVE-2024-34397 is a medium-severity vulnerability (CVSS 5.2) in GNOME GLib affecting versions before 2.78.5 and 2.79.x/2.80.x before 2.80.1. The flaw allows local attackers on shared computers to spoof D-Bus signals that GDBus-based clients will incorrectly attribute to trusted system services like NetworkManager. This signal spoofing can cause affected clients to behave incorrectly with application-depen [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-33602

CVE-2024-33602 is a local memory-corruption flaw in glibc’s nscd netgroup cache. In Siemens advisory ICSA-25-162-05, the issue is mapped to several SIMATIC S7-1500 CPU 1518/1518F MFP variants and a SIPLUS variant, with no fix available at the time of the advisory. The main defensive takeaway is to reduce who can access the affected device’s additional GNU/Linux subsystem and keep execution limited to trus [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-33601

CVE-2024-33601 is a denial-of-service vulnerability in the GNU C Library nscd netgroup cache. According to the supplied advisory material, memory allocation failures in xmalloc or xrealloc can terminate the nscd process, disrupting clients that depend on it. Siemens’ advisory context ties the issue to specific SIMATIC S7-1500 CPU variants that include an additional GNU/Linux subsystem. The flaw was introd [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-33600

CVE-2024-33600 is a medium-severity availability issue mapped by CISA and Siemens to five SIMATIC S7-1500 CPU product variants. The underlying flaw is a null pointer dereference in nscd after a notfound netgroup response if the cache fails to store the result. The source advisory states that no fix is currently available, so defense centers on limiting access to the additional GNU/Linux subsystem and usin [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2024-33599

CVE-2024-33599 is a high-severity stack-based buffer overflow in nscd netgroup cache handling, described in Siemens and CISA advisory material for specific SIMATIC S7-1500 CPU family products with an additional GNU/Linux subsystem. The source states that no fix is currently available, so affected environments should rely on compensating controls and Siemens/CISA guidance.

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-12243

CVE-2024-12243 is a denial-of-service issue tracked in Siemens' SIMATIC S7-1500 CPU family advisory. The flaw is described as inefficient ASN.1/DER certificate processing in the GnuTLS/libtasn1 path, which can consume excessive resources when handling specially crafted certificate data. Siemens and CISA identify affected SIMATIC S7-1500 CPU variants and note that no fix was available in the advisory, so e [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2024-12133

CVE-2024-12133 is a denial-of-service issue tied to libtasn1 certificate handling and documented by CISA in Siemens advisory ICSA-25-162-05. On the affected Siemens SIMATIC S7-1500 CPU family products, specially crafted certificate data with a large number of elements can take much longer than expected to process, which may slow the system or cause a crash. The supplied advisory notes that no fix is curre [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2023-52927

CVE-2023-52927 is published in Siemens’ SIMATIC S7-1500 CPU family advisory and is assessed at medium severity with an availability-only impact profile. The advisory says no fix is currently available for the listed CPU variants. Siemens recommends limiting access to the additional GNU/Linux subsystem to trusted personnel and only building or running applications from trusted sources.

HIGH Siemens CVE published 2025-06-10

CVE-2023-38545

CVE-2023-38545 is a critical heap-based buffer overflow in curl/libcurl's SOCKS5 proxy handshake path. If a handshake is slow and curl mis-evaluates whether the proxy should resolve a hostname, it can copy an overlong hostname into a heap buffer instead of only the resolved address. The CVSS v3.1 score is 9.8, reflecting network reachability, no privileges or user interaction, and high impact.

MEDIUM Siemens CVE published 2025-05-30

CVE-2025-4598

A race condition vulnerability in systemd-coredump affects Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP devices. The flaw allows an attacker with local access to force a SUID process to crash, then exploit PID recycling to gain access to privileged process coredump data before systemd-coredump can analyze /proc/pid/auxv. Successful exploitation could expose sensitive memory contents such as /etc/shadow. T [truncated]

MEDIUM Siemens CVE published 2025-05-14

CVE-2025-1688

CVE-2025-1688 describes an upgrade-path weakness in the installer for the affected video management product line. According to the supplied advisory text, upgrading with specific 2024 R1 or 2024 R2 installers can reset the optional system configuration password on the Management Server. The vendor states there is currently no fix available and recommends resetting the system configuration password through [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40583

CVE-2025-40583 is a confidentiality issue affecting Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2). The advisory says affected devices transmit sensitive information in cleartext, which could let a privileged local attacker retrieve that information. Siemens and CISA list no fix at the time of publication, so access controls are the primary defense.

HIGH Siemens CVE published 2025-05-13

CVE-2025-40582

CVE-2025-40582 is a high-severity Siemens advisory affecting the SCALANCE LPE9403 (6GK5998-3GS00-2AC2). According to the CISA CSAF advisory published on 2025-05-13, affected devices do not properly sanitize configuration parameters, which could allow a non-privileged local attacker to execute root commands on the device. The advisory states that no fix is currently available, so defenders should rely on a [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-40581

CVE-2025-40581 is a high-severity authentication bypass affecting Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2). According to the advisory, a non-privileged local attacker could bypass authentication of the SINEMA Remote Connect Edge Client and read or modify configuration parameters. Siemens’ advisory and the CISA CSAF publication both state that no fix is currently available, so access restriction and o [truncated]

LOW Siemens CVE published 2025-05-13

CVE-2025-58903

CVE-2025-58903 is a low-CVSS availability issue in the supplied CISA/Siemens CSAF for Siemens RUGGEDCOM APE1808. The issue is described as an unchecked return value leading to a null pointer dereference that can crash the HTTP daemon when an authenticated user sends a specially crafted request. In operational environments, even a low-scoring denial-of-service issue can matter because it may disrupt device [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-57740

CVE-2025-57740 is a HIGH-severity heap-based buffer overflow reported in an RDP bookmark connection path. The advisory text says an authenticated user may be able to execute unauthorized code via crafted requests. The published CVSS v3.1 score is 7.5, reflecting network attackability with elevated requirements and high potential impact.

LOW Siemens CVE published 2025-05-13

CVE-2025-54821

The supplied CISA/Siemens advisory for CVE-2025-54821 describes an improper privilege management issue in which an authenticated administrator may bypass trusted-host policy through a crafted CLI command. The advisory metadata maps the issue to Siemens RUGGEDCOM APE1808, but the CVE description text in the supplied corpus names Fortinet FortiOS/FortiPAM/FortiProxy versions, so asset owners should validate [truncated]