PatchSiren

siemens CVE debriefs · Page 41

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2025-05-13

CVE-2025-53843

CVE-2025-53843 is described in the supplied source as a stack-based buffer overflow that may allow unauthorized code or command execution via specially crafted packets. In the CISA-republished advisory data, the affected product is Siemens RUGGEDCOM APE1808, and the record was updated again on 2026-02-12. However, the same source corpus also embeds Fortinet FortiOS/FortiGate product text in the CVE descri [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-53744

CVE-2025-53744 is described in the supplied advisory record as a high-severity privilege assignment issue (CWE-266) that could let a remote authenticated attacker with high privileges escalate to super-admin by registering a device to a malicious FortiManager. The record is also internally inconsistent: the advisory metadata maps the issue to Siemens RUGGEDCOM APE1808, while the vulnerability description [truncated]

LOW Siemens CVE published 2025-05-13

CVE-2025-47890

CVE-2025-47890 describes a CWE-601 URL redirection to an untrusted site issue that may let an unauthenticated attacker trigger an open redirect through crafted HTTP requests. The advisory rates it low severity (CVSS 2.6), but the issue can still be useful for phishing or trust abuse when exposed services are reachable. The supplied source set also contains a notable metadata mismatch: the advisory text na [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-40591

CVE-2025-40591 is a high-severity Siemens RUGGEDCOM ROX web-interface flaw disclosed on 2025-05-13. The issue is in the Log Viewers tool, where missing server-side input sanitization can let an authenticated remote attacker trigger command injection. The advisory states this could execute the tail command with root privileges and expose filesystem contents. Siemens and CISA list 11 affected RUGGEDCOM ROX [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40580

CVE-2025-40580 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) and was published on 2025-05-13. The advisory says a stack-based buffer overflow could allow a non-privileged local attacker to execute arbitrary code on the device or trigger a denial-of-service condition. Siemens/CISA list no fix available at publication time and recommend restricting access to authorized and trusted personnel only.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40579

CVE-2025-40579 affects Siemens SCALANCE LPE9403 devices and is described as a stack-based buffer overflow. According to the supplied advisory data, a non-privileged local attacker could potentially execute arbitrary code on the device or trigger a denial of service. The advisory also states that no fix is currently available, so the immediate defense is to restrict access to authorized and trusted personn [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40578

Published on 2025-05-13, CVE-2025-40578 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2). An unauthenticated attacker on an adjacent network can send multiple Profinet packets in rapid succession, which can crash the dcpd process. CISA rates the issue CVSS 4.3/Medium and reports that no fix is currently available.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40577

CVE-2025-40577 is a Siemens SCALANCE LPE9403 issue in which incoming Profinet packets are not properly validated. According to the advisory, an attacker can trigger a crash of the dcpd process by sending a specially crafted packet. Siemens/CISA list no fix at publication time and recommend disabling the Profinet Discovery and Configuration Protocol (DCP) service where feasible.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40576

CVE-2025-40576 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) and involves insufficient validation of incoming Profinet packets. According to the advisory, an unauthenticated attacker on an adjacent network can send a specially crafted packet that causes the dcpd process to crash. The impact is availability-only, and Siemens listed a mitigation to disable the Profinet Discovery and Configuration Pr [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40575

CVE-2025-40575 is a Siemens SCALANCE LPE9403 issue disclosed on 2025-05-13 in CISA advisory ICSA-25-135-18. The advisory says affected devices do not properly validate incoming Profinet packets, and an unauthenticated attacker on an adjacent network can send a specially crafted packet that crashes the dcpd process. The published CVSS v3.1 vector is AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, which aligns with a [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-40574

CVE-2025-40574 is a high-severity local authorization issue affecting Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2). According to the CISA/Siemens advisory, affected devices do not properly assign permissions to critical resources, which could let a non-privileged local attacker interact with the backupmanager service. The advisory states that no fix was available at publication, so risk reduction depends [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40573

CVE-2025-40573 affects Siemens SCALANCE LPE9403 devices. According to the advisory, a path traversal weakness could allow a privileged local attacker to restore backups from outside the intended backup folder. The issue was published by CISA on 2025-05-13 and carries a CVSS v3.1 score of 4.4 (Medium). At publication time, Siemens indicated there was no fix available and recommended restricting access to a [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40572

CVE-2025-40572 affects Siemens SCALANCE LPE9403 and was published on 2025-05-13. The issue is an improper permissions problem on critical resources that could let a non-privileged local attacker access sensitive information stored on the device. The advisory classifies the issue as medium severity and notes that no fix was available at publication, with mitigation focused on restricting access to authoriz [truncated]

LOW Siemens CVE published 2025-05-13

CVE-2025-40571

CVE-2025-40571 is a low-severity access-control issue in Siemens' Mendix OIDC SSO module. The module's OIDC.Token entity is configured so only the Administrator role can read and write tokens, and Siemens warns this could lead to privilege misuse if an adversary modifies the module during Mendix development.

HIGH Siemens CVE published 2025-05-13

CVE-2025-40566

CVE-2025-40566 is a high-severity Siemens SIMATIC PCS neo vulnerability in which user sessions are not correctly invalidated on logout. If an attacker has already obtained a valid session token by other means, they may be able to reuse that session after the legitimate user logs out. Siemens and CISA published the advisory on 2025-05-13, and vendor updates are available for the affected product lines.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40556

CVE-2025-40556 affects Siemens BACnet ATEC 550-440, 550-441, 550-445, and 550-446 devices. According to the CISA CSAF advisory and Siemens security advisory, a specially crafted BACnet MSTP message from an attacker on the same BACnet network can trigger a denial of service condition that requires a power cycle to restore normal operation.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-40555

CVE-2025-40555 is a medium-severity issue in Siemens APOGEE PXC+TALON TC Series (BACnet) devices where a specific BACnet createObject request can cause affected devices to start sending unsolicited BACnet broadcast messages. In a same-network BACnet environment, that behavior can reduce network availability and create a partial denial-of-service condition on the targeted device. Siemens/CISA note that a p [truncated]

CRITICAL Siemens CVE published 2025-05-13

CVE-2025-33025

CVE-2025-33025 is a critical command-injection issue in the web interface traceroute function of affected Siemens RUGGEDCOM ROX devices. Because the flaw can be used by an authenticated remote attacker to execute arbitrary code with root privileges, it should be treated as an urgent patching priority.

CRITICAL Siemens CVE published 2025-05-13

CVE-2025-33024

CVE-2025-33024 is a critical command-injection issue in the tcpdump function of the web interface on affected Siemens RUGGEDCOM ROX devices. According to the supplied advisory text, a remote attacker with valid authentication could trigger arbitrary code execution with root privileges. Siemens lists a fix in version V2.16.5 or later for the affected product line.

CRITICAL Siemens CVE published 2025-05-13

CVE-2025-32469

CVE-2025-32469 is a critical command-injection flaw in the web interface ping tool on affected Siemens RUGGEDCOM ROX devices. Because the issue is reachable by an authenticated remote attacker and can lead to root-level arbitrary code execution, it should be treated as an immediate patching priority for exposed or operationally important OT management interfaces.

HIGH Siemens CVE published 2025-05-13

CVE-2025-32454

CVE-2025-32454 affects Siemens Tecnomatix Plant Simulation V2404 when it parses specially crafted WRL files. The flaw is an out-of-bounds read past the end of an allocated structure, and Siemens/CISA note that it could allow code execution in the context of the current process. The issue was publicly disclosed on 2025-06-10, and Siemens provides a fixed release: V2404.0013 or later.

HIGH Siemens CVE published 2025-05-13

CVE-2025-31930

CVE-2025-31930 affects multiple Siemens VersiCharge AC and related EV charger products because Modbus service is enabled by default. According to the CISA CSAF advisory and Siemens references, an attacker already connected to the same network could use that service to remotely control the charger. The published CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the potential for high-impact co [truncated]

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-31929

CVE-2025-31929 affects multiple Siemens VersiCharge AC Series EV charger models. According to the CISA CSAF advisory and Siemens product advisory, the affected devices do not contain an immutable root of trust in M0 hardware. A physical attacker could use that weakness to execute arbitrary code. Siemens lists no fix planned for the affected products.

LOW Siemens CVE published 2025-05-13

CVE-2025-31514

CVE-2025-31514 describes an information-disclosure issue where sensitive 2FA-related data may be exposed through logs or a diagnose command to someone with at least read-only privileges. The public CSAF record ties the issue to Siemens RUGGEDCOM APE1808, but the CVE description text itself names FortiOS versions, so applicability should be verified against the official Siemens advisory before acting.

MEDIUM Siemens CVE published 2025-05-13

CVE-2025-31366

CVE-2025-31366 is described in the supplied record as an unauthenticated reflected cross-site scripting issue triggered by crafted HTTP requests, with a CVSS 3.1 score of 4.7 and a network attack vector that still requires user interaction. However, the same record is internally inconsistent: its metadata and official references point to Siemens RUGGEDCOM APE1808 / SSA-864900, while the vulnerability desc [truncated]

HIGH Siemens CVE published 2025-05-13

CVE-2025-30176

CVE-2025-30176 is a Siemens-advised unauthenticated remote denial-of-service issue in the integrated User Management Component (UMC) used across multiple industrial products. Because the attack is network reachable and requires no authentication, affected operators should treat it as a high-priority availability risk.

HIGH Siemens CVE published 2025-05-13

CVE-2025-30175

CVE-2025-30175 is an out-of-bounds write buffer overflow in Siemens’ integrated User Management Component (UMC). According to the public advisory, an unauthenticated remote attacker could use the flaw to cause a denial-of-service condition in affected products. The issue was publicly disclosed on 2025-05-13 and later updated on 2025-10-14 to reflect additional remediation status.

HIGH Siemens CVE published 2025-05-13

CVE-2025-30174

CVE-2025-30174 is a Siemens OT vulnerability in the integrated User Management Component (UMC) used by several product lines. According to CISA's CSAF advisory, an unauthenticated remote attacker can trigger an out-of-bounds read/buffer overflow condition that may cause denial of service, making this a high-priority availability issue for industrial environments.

CRITICAL Siemens CVE published 2025-05-13

CVE-2025-26390

CVE-2025-26390 is a critical SQL injection affecting the web service authentication check in Siemens OZW672 and OZW772 devices. According to the CISA CSAF advisory and Siemens references, an unauthenticated remote attacker could bypass the check and authenticate as Administrator. Siemens provides a fix in version V6.0 or later for the affected products.

CRITICAL Siemens CVE published 2025-05-13

CVE-2025-26389

CVE-2025-26389 is a critical Siemens OZW Web Servers vulnerability affecting OZW672 and OZW772. According to the CISA CSAF advisory and Siemens references, the web service does not sanitize input parameters for the `exportDiagramPage` endpoint, which can allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Because the attack is network-based and requires no user interac [truncated]