These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-23403 affects Siemens SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor. An authenticated attacker with local access could abuse overly broad registry-key permissions to load vulnerable drivers, potentially escalating privileges or bypassing endpoint protection and other security controls.
CVE-2025-23363 is a Siemens Teamcenter SSO login redirect issue affecting Teamcenter V14.1, V14.2, V14.3, V2312, V2406, and V2412. The vulnerable behavior allows user-controlled input to influence a link to an external site, which can be abused to redirect a legitimate user to an attacker-chosen URL. Because the attack depends on the user clicking a crafted link, this is a user-interaction-driven exposure [truncated]
CVE-2025-22254 is a medium-severity privilege management issue in the supplied advisory set. The source corpus ties the advisory to Siemens RUGGEDCOM APE1808, while the vulnerability text itself describes an authenticated attacker with read-only admin access gaining super-admin privileges through crafted Node.js websocket requests. Because the supplied records contain inconsistent vendor/product details, [truncated]
CVE-2025-22252 is a critical authentication-bypass issue published in the CISA/Siemens advisory record on 2025-02-11. The supplied corpus describes a missing authentication for a critical function that can let an attacker who already knows an existing admin account gain valid admin access under a TACACS+ remote-auth configuration that uses ASCII authentication. Because the source corpus also contains conf [truncated]
CVE-2025-22251 is a low-severity issue published by CISA on 2025-02-11 and updated through 2026-03-12. The source advisory ties the CVE to Siemens RUGGEDCOM APE1808 and describes an improper restriction of communication channels (CWE-923) that may let an unauthenticated attacker inject unauthorized sessions using crafted FGSP session synchronization packets. Because the corpus also contains FortiOS/FortiG [truncated]
CVE-2024-54090 affects Siemens APOGEE PXC Series (BACnet/P2 Ethernet) and TALON TC Series (BACnet). CISA and Siemens describe an out-of-bounds read in the memory dump function that could allow an attacker with Medium (MED) or higher privileges to force the device into an insecure cold start state. The advisory was published on 2025-02-11 and lists mitigations, but no vendor fix was available at publication.
CVE-2024-54021 was published on 2025-02-11 and later republished/updated on 2026-03-12 in CISA's Siemens RUGGEDCOM APE1808 advisory. The source corpus describes an HTTP header CRLF neutralization issue (HTTP response splitting) that could allow unauthorized code or command execution via a crafted HTTP header. The advisory is medium severity (CVSS 6.5) and is network-reachable. The remediation section in t [truncated]
CVE-2024-54015 affects Siemens SIPROTEC 5 devices and related communication modules. The advisory says the devices do not properly validate SNMP GET requests, which can let a remote attacker retrieve sensitive information over SNMPv2. Siemens and CISA recommend restricting access to UDP/161, disabling SNMP if it is not needed, and applying product-specific updates.
CVE-2024-53977 is a local privilege-escalation issue in Siemens ModelSim and Questa. According to the CISA/Siemens advisory, an example setup script can load a specific executable from the current working directory. If an administrator or other elevated process launches that script from a user-writable location, an authenticated local attacker may be able to inject arbitrary code and gain elevated privileges.
CVE-2024-53651 affects Siemens SIPROTEC 5 devices. Certain data in on-board flash storage are not encrypted, so an attacker with physical access could potentially read the device’s entire filesystem. CISA published the advisory on 2025-02-11 and lists mitigations such as limiting physical access and using customer PKI certificates; for many affected variants, no fix is currently available.
CVE-2024-53648 affects a broad set of Siemens SIPROTEC 5 devices and relates to insufficient restriction of a development shell exposed over a physical interface. CISA’s advisory says an unauthenticated attacker with physical access could execute arbitrary commands on the device. Because exploitation requires physical access, this is not a remote attack issue, but it is still important in substations, ind [truncated]
CVE-2024-52965 is a high-severity authentication issue described as a missing critical step in authentication (CWE-304) that can allow API login even when a certificate is invalid. The supplied source corpus is inconsistent, however: the CVE description names Fortinet FortiOS/FortiProxy versions, while the CSAF advisory and product tree identify Siemens RUGGEDCOM APE1808. Treat the advisory as requiring m [truncated]
CVE-2024-50565 was published on 2025-02-11 and later republished/updated on 2026-03-12 in the supplied CISA CSAF record. Based on the source corpus, the affected product is Siemens RUGGEDCOM APE1808, and the advisory links to Siemens ProductCERT SSA-770770. The CVE text describes a man-in-the-middle impersonation scenario involving FGFM authentication and Fortinet management products, so the supplied data [truncated]
CVE-2024-50563 was publicly disclosed on 2025-02-11 and later republished/updated on 2026-03-12. The supplied source corpus describes a high-severity weak-authentication issue that could allow unauthorized code or command execution via brute force, but the record also contains conflicting vendor/product details: the advisory metadata maps it to Siemens RUGGEDCOM APE1808, while the narrative description an [truncated]
CVE-2024-48886 is described in the supplied corpus as a weak-authentication flaw that could let an attacker brute-force access and execute unauthorized code or commands. The advisory metadata is internally inconsistent: the CSAF item is labeled for Siemens RUGGEDCOM APE1808, while the vulnerability text and remediation references point to Fortinet products. Validate exposure against the official advisory [truncated]
CVE-2024-47569 is described in the supplied corpus as a sensitive-information disclosure issue triggered by specially crafted packets. The advisory material in the corpus ties it to Siemens SSA-770770 / CISA ICSA-25-044-06, but the CVE description text itself names multiple Fortinet product families and versions, so applicability should be confirmed directly against the official vendor advisories before remediation.
CVE-2024-46670 is a high-severity denial-of-service issue in the CISA CSAF advisory mapped to Siemens RUGGEDCOM APE1808. The source describes an unauthenticated, network-reachable out-of-bounds read that can consume memory and lead to DoS through crafted requests. Because the attack does not require authentication and affects an exposed service path, operators should treat this as a service-availability r [truncated]
CVE-2024-46669 is a low-severity availability issue described in the CISA-republished Siemens ProductCERT advisory for RUGGEDCOM APE1808. The source text says an authenticated attacker could trigger an integer overflow or wraparound and crash the IPsec tunnel via crafted requests, causing denial of service. The advisory corpus also contains a product-description mismatch that references FortiSASE/FortiOS [truncated]
CVE-2024-46666 was publicly disclosed in the Siemens ProductCERT/CISA advisory on 2025-02-11 and later republised by CISA on 2026-03-12. The supplied corpus describes a remote unauthenticated denial-of-service condition that can prevent access to the GUI through specially crafted requests to specific endpoints. The advisory metadata ties the issue to Siemens RUGGEDCOM APE1808, but the vulnerability descri [truncated]
CVE-2024-46665 is a low-severity information disclosure issue affecting Siemens RUGGEDCOM APE1808. According to the supplied CISA/Siemens advisory corpus, an attacker in a man-in-the-middle position may be able to recover the RADIUS accounting server shared secret by intercepting accounting-requests. The advisory was published on 2025-02-11 and republished/updated on 2026-03-12. No CISA KEV listing is pre [truncated]
CVE-2024-45386 is a session-management weakness in several Siemens products where user logout does not correctly invalidate the session. According to the advisory, an attacker who already obtained a valid session token by other means could reuse that token after logout. The issue was publicly disclosed on 2025-02-11 and later revised on 2025-05-06 for typo fixes only.
CVE-2024-40591 is a high-severity privilege escalation issue in the supplied advisory text. The described flaw affects Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9, and versions before 7.0.15. An authenticated admin with Security Fabric permission may be able to gain super-admin privileges by connecting the targeted FortiGate to a malicious upstream FortiGate they control. The [truncated]
CVE-2024-35279 is a high-severity network-facing vulnerability reported in the supplied advisory corpus and first published by CISA on 2025-02-11. The source data maps the CVE to Siemens RUGGEDCOM APE1808, and later notes a 2026-03-12 CISA republication update based on Siemens ProductCERT SSA-770770. The advisory text in the corpus also contains an upstream Fortinet FortiOS CAPWAP/UDP buffer-overflow desc [truncated]
CVE-2024-33016 is a Siemens SCALANCE W700 issue reported by CISA as memory corruption triggered when an invalid firehose patch command is invoked. Siemens rates the issue for multiple SCALANCE wireless access point models, and the published remediation is to update affected devices to V3.0.0 or later. Because the CVSS vector includes physical access requirements, the exposure is more constrained than a re [truncated]
CVE-2024-26013 is a CVSS 7.5 improper restriction of communication channel issue that can let an unauthenticated attacker in a man-in-the-middle position impersonate a management device by intercepting FGFM authentication traffic. In the supplied corpus, the advisory is published by CISA in the context of Siemens RUGGEDCOM APE1808, but the vulnerability text and remediation reference Fortinet products, so [truncated]
CVE-2023-7250 describes a denial-of-service condition in iperf used by several Siemens SCALANCE W700 product variants. According to the advisory, a malicious or malfunctioning client can send less data than expected, causing the iperf server to wait indefinitely for the remainder or until the connection closes. In an affected deployment, that hang can prevent other connections from being served. Siemens’ [truncated]
CVE-2023-37482 is a timing side-channel issue in the web server login function used by multiple Siemens SIMATIC products. According to the CISA CSAF advisory published on 2025-02-11, the affected web login path does not normalize response times, allowing an unauthenticated remote attacker to distinguish valid from invalid usernames. The advisory was revised on 2025-05-06 for typo fixes. Siemens and CISA l [truncated]
CVE-2023-31315 is a Siemens SCALANCE W700 advisory item published by CISA on 2025-02-11. The issue involves improper validation of a model specific register (MSR) that could let a malicious program with ring0 access modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
CVE-2023-28578 is a critical memory-corruption vulnerability in Siemens Core Services affecting multiple SCALANCE W700 device models. Siemens and CISA describe the issue as occurring while executing the command for removing a single event listener. The advisory assigns a CVSS v3.1 score of 9.3 and recommends updating affected products to V3.0.0 or later.
CVE-2023-1118 is a high-severity local use-after-free in the Linux kernel’s integrated infrared receiver/transceiver driver. According to the advisory corpus, a local user detaching an rc device could trigger a crash and potentially gain elevated privileges. CISA’s CSAF advisory ties the issue to multiple Siemens SCALANCE W700 IEEE 802.11ax products and points to Siemens’ fix guidance to update to V3.0.0 or later.