These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-23402 is a use-after-free vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation when parsing specially crafted WRL files. The issue can lead to code execution in the context of the current process, and the supplied CVSS vector indicates local access plus user interaction are required. Siemens and CISA published remediation guidance on 2025-03-11, with a later 2025-05-0 [truncated]
CVE-2025-23401 is a high-severity Siemens vulnerability affecting Teamcenter Visualization V14.3, V2312, V2406, V2412 and Tecnomatix Plant Simulation V2302, V2404. Siemens and CISA say the flaw is an out-of-bounds read past the end of an allocated structure while parsing specially crafted WRL files. The advisory states this could allow code execution in the context of the current process. The advisory was [truncated]
CVE-2025-23400 is a Siemens product vulnerability disclosed by CISA on 2025-03-11 and revised on 2025-05-06 for typo fixes. Affected Teamcenter Visualization and Tecnomatix Plant Simulation versions can experience memory corruption while parsing specially crafted WRL files, which may allow code execution in the context of the current process. Siemens has published fixed versions for each affected product [truncated]
CVE-2025-23399 is a high-severity Siemens memory-safety issue in Teamcenter Visualization and Tecnomatix Plant Simulation. According to the CISA/Siemens advisory, parsing specially crafted WRL files can trigger an out-of-bounds read past the end of an allocated structure, which could allow code execution in the context of the current process. The advisory was published on 2025-03-11 and later revised on 2 [truncated]
CVE-2025-23398 is a high-severity Siemens issue in Teamcenter Visualization and Tecnomatix Plant Simulation. According to the advisory, specially crafted WRL files can trigger memory corruption during parsing, which may allow code execution in the context of the current process. The CISA advisory was published on 2025-03-11 and later revised on 2025-05-06 for typos only.
CVE-2025-23397 is a Siemens vulnerability disclosed on 2025-03-11 that affects Teamcenter Visualization and Tecnomatix Plant Simulation products. The issue is a memory corruption condition during parsing of specially crafted WRL files, which could let an attacker execute code in the context of the current process. The advisory was revised on 2025-05-06 for typo fixes only, not a new issue date. From a def [truncated]
CVE-2025-23396 was published on 2025-03-11 and later revised on 2025-05-06 with typo-only changes in the CISA advisory. Siemens and CISA say affected Teamcenter Visualization and Tecnomatix Plant Simulation versions can hit an out-of-bounds write while parsing a specially crafted WRL file, which could allow code execution in the context of the current process. The safest immediate response is to avoid ope [truncated]
CVE-2025-23384 is a network-reachable authentication flaw in multiple Siemens RUGGEDCOM and SCALANCE router and firewall families. The affected devices improperly validate usernames during OpenVPN authentication, which can allow partial invalid usernames to be accepted by the server. NVD rates the issue CVSS 6.3 (MEDIUM).
CISA’s CSAF advisory for Siemens SIMATIC S7-1500 TM MFP - BIOS was published on 2025-03-11 and later revised on 2025-09-09. The supplied vulnerability description says the child qdisc backlog must be reduced before qdisc_tree_reduce_backlog() is called; otherwise parent notification can be missed, and in the DRR case that could lead to a use-after-free because qlen_notify() maintains the active list. At p [truncated]
CVE-2024-56336 affects Siemens SINAMICS S200 and is described by CISA as an unlocked bootloader security oversight. If the bootloader is not secured, an attacker may be able to inject malicious code or install untrusted firmware, undermining the device’s protections against unauthorized access and data manipulation. The advisory was published on 2025-03-11 and rates the issue CVSS 3.1 9.8 (Critical).
CVE-2024-52285 affects Siemens SiPass integrated AC5102 (ACC-G2) and ACC-AP. The advisory says several MQTT URLs are exposed without authentication, which could let an unauthenticated remote attacker access sensitive data. Siemens lists a fix in V6.4.8 or later; the issue is rated CVSS 5.3 (MEDIUM).
CVE-2024-4877 is a Siemens SINEMA Remote Connect Client issue publicly disclosed by CISA and Siemens on 2025-03-11. The advisory says an attacker with SeImeprsonatePrivilege who can create a named-pipe server using the same name as the "Interactive Service" may be able to impersonate the user running a connecting UI such as OpenVPN-GUI. Siemens' remediation is to update to V3.2 SP3 or later.
CVE-2024-42513 is a critical authentication-bypass vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158. Siemens’ advisory says an unauthorized attacker can bypass application authentication when HTTPS endpoints are used. The issue was published by CISA on 2025-03-11 and later republished on 2026-01-14 with Siemens ProductCERT advisory SSA-858251. For some affected products, Siemens notes th [truncated]
CVE-2024-42512 is a Siemens-disclosed authentication bypass affecting the OPC UA .NET Standard Stack before version 1.5.374.158. The issue is conditional: it applies when the deprecated Basic128Rsa15 security policy is enabled, and the CISA CSAF advisory maps it to multiple Siemens products including SIMATIC Energy Manager PRO V7.2-V7.5 and SIMIT V11. Updates are available for some affected products, whil [truncated]
CVE-2024-27903 is a critical issue affecting Siemens SINEMA Remote Connect Client on Windows. The advisory says OpenVPN plug-ins in OpenVPN 2.6.9 and earlier could be loaded from any directory, enabling an attacker to load an arbitrary plug-in and interact with the privileged OpenVPN interactive service.
CVE-2024-27459 is a high-severity advisory affecting Siemens SINEMA Remote Connect Client. The supplied advisory metadata says the flaw can let an attacker send data that triggers a stack overflow and may lead to arbitrary code execution with more privileges. Siemens' remediation is to update to V3.2 SP3 or later.
CVE-2024-24974 was publicly disclosed in CISA’s ICSA-25-072-10 advisory on 2025-03-11. The advisory ties the issue to Siemens SINEMA Remote Connect Client and describes a remote-access weakness in the OpenVPN interactive service that could let an attacker interact with a privileged service interface. Siemens provides an update path to V3.2 SP3 or later.
CVE-2024-1305 is a critical memory corruption issue affecting Siemens SINEMA Remote Connect Client. The supplied advisory describes an overflow in the tap-windows6 driver caused by improper size checking on incoming write operations, which can trigger a bug check and may allow arbitrary code execution in kernel space. Because the CVSS vector is network-reachable, requires no privileges, and needs no user [truncated]
CVE-2025-21772 is a HIGH severity vulnerability (CVSS 7.1) affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control systems. The vulnerability stems from improper handling of malformed partition tables in the mac partition driver, which could allow a local attacker with low privileges to cause denial of service or potentially read sensitive information. The issue was first pu [truncated]
CVE-2025-21762 is a Linux kernel availability vulnerability that Siemens mapped to SIMATIC S7-1500 TM MFP - BIOS in its industrial advisory. The kernel issue is described as a missing RCU-protection problem in arp_xmit(), which could create a potential use-after-free condition when the function is called without RTNL or RCU protection. For defenders, the main concern is service disruption rather than data [truncated]
CVE-2025-21735 is a HIGH severity vulnerability (CVSS 7.8) affecting the NFC (Near Field Communication) subsystem in the Linux kernel, specifically within the nci_hci_create_pipe() function. The vulnerability stems from missing bounds checking that could lead to out-of-bounds access. Siemens has identified this as affecting the GNU/Linux subsystem of their SIMATIC S7-1500 TM MFP industrial control product [truncated]
CVE-2025-21719 is a vulnerability in the Linux kernel's IP multicast routing (ipmr) subsystem. The issue occurs when the kernel incorrectly calls `mr_mfc_uses_dev()` on unresolved multicast forwarding cache (MFC) entries, which can lead to a denial of service condition. The vulnerability has a CVSS 3.1 score of 5.5 (MEDIUM severity) with a local attack vector requiring low privileges. Siemens has identifi [truncated]
CVE-2024-57986 is a vulnerability in the Linux kernel's HID (Human Interface Device) core subsystem. The flaw stems from an incorrect assumption that Resolution Multipliers must be located within Logical Collections in HID report descriptors. This assumption can lead to improper input handling and potential denial of service conditions when processing malformed HID reports. The vulnerability was published [truncated]
CVE-2025-26465 affects multiple Siemens SIMATIC S7-1500 CPU family products and is tied to OpenSSH behavior when VerifyHostKeyDNS is enabled. According to the advisory, a successful machine-in-the-middle attack requires the attacker to first exhaust the client’s memory resources, which raises the attack complexity, and Siemens notes that no fix is currently available.
CVE-2025-26491 is a HIGH-severity server-side request forgery (SSRF) issue published by CISA on 2025-02-11 and revised on 2025-05-06 for typo fixes. The source corpus identifies Siemens Opcenter Intelligence as the affected product, but the vulnerability description and remediation text refer to Tableau Server, so applicability should be verified against the linked Siemens advisory before acting. No KEV l [truncated]
CVE-2025-26490 is a medium-severity disclosure issue tracked in a CISA ICS advisory for Siemens Opcenter Intelligence. The supplied advisory text contains an internal product-description mismatch, so defenders should rely on the official Siemens/CISA references and verify applicability before acting.
CVE-2025-24956 affects Siemens OpenV2G and stems from a missing length check while parsing X509 serial numbers in EXI data. Siemens and CISA describe the issue as a buffer overflow that can lead to memory corruption; the provided CVSS vector rates it medium severity, with high availability impact. A vendor fix is available in OpenV2G 0.9.6 or later.
CVE-2025-24812 is a denial-of-service issue in multiple Siemens SIMATIC S7-1200 and SIPLUS S7-1200 CPU variants. The advisory says specially crafted packets sent to TCP port 102 are not processed correctly, which could interrupt device availability. Siemens remediation is to update affected products to V4.7 or later.
CVE-2025-24532 is a Siemens SCALANCE issue in SNMPv3 View configuration authorization. According to the advisory, devices with the `user` role are affected by incorrect authorization that could let an attacker change the View Type of SNMPv3 Views. Siemens lists a fix in V3.0.0 or later for the affected SCALANCE WAB/WAM/WUB/WUM models. The published CVSS score is 4.3 (Medium), reflecting a network-reachabl [truncated]
CVE-2025-24499 is a high-severity Siemens advisory affecting multiple SCALANCE W700 IEEE 802.11ax device variants. The issue is an input-validation flaw in configuration file loading that could let an authenticated remote attacker execute arbitrary shell commands on the device. Siemens and CISA both published the issue on 2025-02-11, and the later 2025-05-06 revision was limited to typo fixes. Siemens sta [truncated]