PatchSiren

siemens CVE debriefs · Page 45

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Siemens CVE published 2025-04-08

CVE-2025-1974

CVE-2025-1974 was published on 2025-04-08 and is rated Critical (CVSS 9.8). In the supplied advisory corpus, Siemens Insights Hub Private Cloud is the affected product. The underlying issue is described as a Kubernetes security problem where, under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx control [truncated]

HIGH Siemens CVE published 2025-04-08

CVE-2025-1098

CVE-2025-1098 is a high-severity issue publicly disclosed on 2025-04-08. In the Siemens Insights Hub Private Cloud advisory, the underlying problem is in ingress-nginx: the mirror-target and mirror-host Ingress annotations can inject arbitrary nginx configuration. The stated impact includes arbitrary code execution in the ingress-nginx controller context and disclosure of Secrets accessible to that contro [truncated]

HIGH Siemens CVE published 2025-04-08

CVE-2025-1097

CVE-2025-1097 is a high-severity issue mapped by Siemens to Insights Hub Private Cloud through the ingress-nginx component. The advisory says the auth-tls-match-cn Ingress annotation can be abused to inject nginx configuration, which may lead to arbitrary code execution in the ingress-nginx controller context and disclosure of Secrets accessible to that controller. Siemens notes that, in the default insta [truncated]

CRITICAL Siemens CVE published 2025-04-08

CVE-2024-54092

CVE-2024-54092 is a critical authentication-bypass issue in Siemens Industrial Edge Device Kit. When identity federation has been used, an unauthenticated remote attacker who knows a legitimate user identity may be able to bypass authentication on specific API endpoints and impersonate that user. CISA published the advisory on 2025-04-08 and later clarified the affected version lines and fix status on 2025-05-13.

MEDIUM Siemens CVE published 2025-04-08

CVE-2024-41796

CVE-2024-41796 affects Siemens SENTRON 7KT PAC1260 Data Manager web interfaces and is publicly documented in the 2025-04-08 CISA/Siemens advisory set. The issue is not a standalone password reset bypass by itself in the advisory’s framing; rather, it becomes dangerous when combined with a prepared CSRF attack (CVE-2024-41795), which can allow an unauthenticated attacker to set the login password to an att [truncated]

MEDIUM Siemens CVE published 2025-04-08

CVE-2024-41795

CVE-2024-41795 is a medium-severity CSRF issue affecting the web interface of Siemens SENTRON 7KT PAC1260 Data Manager. According to the 2025-04-08 advisory, an unauthenticated attacker could change arbitrary device settings if a legitimate administrator is tricked into clicking a malicious link while logged in. The advisory states that no fix is currently planned and recommends avoiding untrusted links d [truncated]

CRITICAL Siemens CVE published 2025-04-08

CVE-2024-41794

CVE-2024-41794 affects Siemens SENTRON 7KT PAC1260 Data Manager devices that contain hardcoded credentials for remote access to the device operating system with root privileges. If an attacker has those credentials and SSH is enabled, they may gain full access to the device. The advisory is rated CVSS 10.0/CRITICAL, and Siemens currently reports that no fix is planned.

HIGH Siemens CVE published 2025-04-08

CVE-2024-41793

CVE-2024-41793 affects Siemens SENTRON 7KT PAC1260 Data Manager devices. According to the CISA CSAF advisory, the web interface exposes an endpoint that can enable SSH service without authentication, allowing a remote attacker to turn on remote access to the device. The advisory rates the issue HIGH with a CVSS v3.1 score of 8.6, and states that no fix is currently planned. Because the issue is network re [truncated]

HIGH Siemens CVE published 2025-04-08

CVE-2024-41792

CVE-2024-41792 affects Siemens SENTRON 7KT PAC1260 Data Manager devices and was published on 2025-04-08. The issue is a path traversal vulnerability in the web interface that could let an unauthenticated attacker access arbitrary files on the device with root privileges. Siemens’ advisory notes that no fix is currently planned, so exposure reduction and compensating controls are especially important.

HIGH Siemens CVE published 2025-04-08

CVE-2024-41791

CVE-2024-41791 describes a web-interface authentication failure in Siemens SENTRON 7KT PAC1260 Data Manager. According to the CISA CSAF advisory published on 2025-04-08, affected devices do not authenticate report creation requests, which could let an unauthenticated remote attacker read or clear log files, reset the device, or set the date and time. Siemens’ advisory referenced in the source corpus state [truncated]

CRITICAL Siemens CVE published 2025-04-08

CVE-2024-41790

CVE-2024-41790 is a critical vulnerability in Siemens SENTRON 7KT PAC1260 Data Manager devices. The affected web interface fails to sanitize the region parameter in specific POST requests, which can let an authenticated remote attacker execute arbitrary code with root privileges.

CRITICAL Siemens CVE published 2025-04-08

CVE-2024-41789

On 2025-04-08, CISA published CVE-2024-41789 for Siemens SENTRON 7KT PAC1260 Data Manager. The issue affects the device web interface and can allow an authenticated remote attacker to execute arbitrary code with root privileges. Siemens and CISA list no fix as currently planned, which makes compensating controls especially important.

CRITICAL Siemens CVE published 2025-04-08

CVE-2024-41788

CVE-2024-41788 is a critical Siemens issue affecting the SENTRON 7KT PAC1260 Data Manager web interface. According to the advisory, specific GET request parameters are not sanitized, which can allow an authenticated remote attacker to execute arbitrary code with root privileges. The source corpus also states that no fix is currently planned, so compensating controls are important.

MEDIUM Siemens CVE published 2025-04-08

CVE-2024-23814

CVE-2024-23814 describes a network-reachable denial-of-service condition in the integrated ICMP service used by affected Siemens devices, including SIDOOR ATD430W. Siemens and CISA say an unauthenticated remote attacker can send specially crafted messages that target IP fragment re-assembly and exhaust available memory in the ICMP service. The impact is limited to a temporary ICMP service outage; other co [truncated]

MEDIUM Siemens CVE published 2025-04-08

CVE-2024-21319

CVE-2024-21319 is a Siemens SIDIS Prime vulnerability described by CISA as a Microsoft Identity denial-of-service issue. The published CVSS vector indicates a network-reachable attack that requires high privileges, no user interaction, and can impact availability. Siemens’ remediation guidance is to update SIDIS Prime to V4.0.700 or later.

HIGH Siemens CVE published 2025-04-08

CVE-2022-21658

CVE-2022-21658 is a race-condition flaw described in the supplied Siemens/CISA advisory for SIDIS Prime. The issue involves Rust’s std::fs::remove_dir_all and can let a local attacker influence a privileged deletion operation so files or directories outside the intended scope are removed. Siemens’ advisory recommends updating SIDIS Prime to V4.0.700 or later. The advisory was published on 2025-04-08 and r [truncated]

HIGH Siemens CVE published 2025-03-13

CVE-2025-25175

CVE-2025-25175 is a high-severity memory corruption issue in Siemens Simcenter Femap when parsing specially crafted .NEU files. Per the advisory, an attacker could potentially cause code execution in the context of the current process if a user opens a malicious file. Siemens and CISA recommend avoiding untrusted NEU files and applying the fixed releases.

HIGH Siemens CVE published 2025-03-12

CVE-2025-21844

A vulnerability in the SMB client implementation within the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP could allow a local, authenticated attacker to cause a denial-of-service condition. The issue stems from a missing null pointer check for `next_buffer` in the `receive_encrypted_standard()` function, which may lead to a crash when processing malformed SMB encrypted responses. The vulnerability [truncated]

HIGH Siemens CVE published 2025-03-11

CVE-2024-56182

CVE-2024-56182 describes a weakness in how EFI variables are protected on a broad set of Siemens SIMATIC Field PG and IPC devices. A local, authenticated attacker with high privileges could interact with the flash controller and disable the BIOS password without authorization. NVD rates the issue 8.4 (HIGH).

HIGH Siemens CVE published 2025-03-11

CVE-2024-56181

CVE-2024-56181 is a high-severity weakness in multiple Siemens SIMATIC industrial PC and Field PG products where EFI variables are not sufficiently protected on the device. According to the vendor description, an authenticated attacker with the required access could communicate directly with the flash controller and alter secure boot configuration without proper authorization. That raises concern for devi [truncated]

HIGH Siemens CVE published 2025-03-11

CVE-2025-27493

CVE-2025-27493 describes an input-sanitization flaw in the telnet command-line interface of affected Siemens SiPass integrated devices. According to the CISA CSAF advisory and Siemens advisory, an authenticated local administrator can inject arbitrary commands that execute with root privileges, creating a local privilege-escalation path. Siemens and CISA list affected products as SiPass integrated AC5102 [truncated]

HIGH Siemens CVE published 2025-03-11

CVE-2025-27438

CVE-2025-27438 is a Siemens vulnerability in Teamcenter Visualization and Tecnomatix Plant Simulation that can be triggered while parsing specially crafted WRL files. The issue is an out-of-bounds read past the end of an allocated structure and, according to the advisory, could allow code execution in the context of the current process. Siemens and CISA list fixes for multiple product branches, and the ve [truncated]

LOW Siemens CVE published 2025-03-11

CVE-2025-27398

CVE-2025-27398 affects Siemens SCALANCE LPE9403. Siemens and CISA describe a path handling issue where special characters are not properly neutralized when interpreting user-controlled log paths. In the reported scenario, an authenticated, highly privileged remote attacker could leverage the flaw to execute a limited set of binaries already present on the device. CISA rates the issue LOW with CVSS 2.7, an [truncated]

LOW Siemens CVE published 2025-03-11

CVE-2025-27397

CVE-2025-27397 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) and is described by CISA as a log path handling weakness. The advisory states that user-controlled paths used to write logs and read them back are not properly limited. As a result, an authenticated, highly privileged remote attacker could read and write arbitrary files on the filesystem if the malicious path ends with "log". The advisor [truncated]

HIGH Siemens CVE published 2025-03-11

CVE-2025-27395

CVE-2025-27395 is a high-severity issue in Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) affecting SFTP access controls. According to the CISA CSAF advisory, affected devices do not properly limit the scope of files accessible through SFTP or the privileges associated with that functionality. In practical terms, an authenticated remote attacker with high privileges could read and write arbitrary files on [truncated]

HIGH Siemens CVE published 2025-03-11

CVE-2025-27394

CVE-2025-27394 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2). According to the advisory, the device does not properly sanitize user input when creating new SNMP users, which could allow an authenticated, highly privileged remote attacker to execute arbitrary code on the device. Siemens lists remediation as updating to V4.0 or later.

HIGH Siemens CVE published 2025-03-11

CVE-2025-27393

CVE-2025-27393 is a high-severity Siemens advisory affecting the SCALANCE LPE9403 (6GK5998-3GS00-2AC2). The issue is in how user input is sanitized when creating new users. According to the advisory, an authenticated, highly privileged remote attacker could exploit the weakness to execute arbitrary code on the device. Siemens lists a fix in V4.0 or later.

HIGH Siemens CVE published 2025-03-11

CVE-2025-27392

CVE-2025-27392 affects Siemens SCALANCE LPE9403 devices and involves improper sanitization of user input when creating new VXLAN configurations. According to the advisory, an authenticated, highly privileged remote attacker could leverage the flaw to execute arbitrary code on the device. CISA published the advisory on 2025-03-11 and later revised it on 2025-05-06 for typo fixes only.

MEDIUM Siemens CVE published 2025-03-11

CVE-2025-25267

CVE-2025-25267 affects Siemens Tecnomatix Plant Simulation V2302 and V2404. According to the vendor and CISA advisory, the application does not properly restrict the scope of files accessible to the simulation model, which can expose confidential system data to an unauthorized attacker. CISA published the advisory on 2025-03-11 and later revised it on 2025-05-06 for typo fixes.

MEDIUM Siemens CVE published 2025-03-11

CVE-2025-25266

CVE-2025-25266 is a medium-severity access-control issue in Siemens Tecnomatix Plant Simulation that can allow unauthorized file deletion. CISA’s advisory describes the problem as insufficient restriction on file deletion functionality, which could lead to data loss or modification of system files. Siemens and CISA list fixed versions for both affected release trains.