These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2023-1074 is a denial-of-service issue affecting Siemens SCALANCE W700 IEEE 802.11ax products. The underlying flaw is a Linux kernel Stream Control Transmission Protocol (SCTP) memory leak that can be triggered when a malicious networking service is started and a connection is made to it, allowing a local user to consume resources until service impact occurs. Siemens and CISA list 19 affected SCALANCE [truncated]
CVE-2023-0045 is a medium-severity issue described in Siemens’ ICS advisory for SCALANCE W-series products. The advisory says the Linux prctl-based mitigation for indirect branch prediction barriers (IBPB) is not issued immediately when the syscall runs; instead, the task flags are updated and IBPB is only triggered on the next schedule check. That creates a short exposure window where previously injected [truncated]
Siemens, via CISA advisory ICSA-25-044-09, reported that multiple SCALANCE W700 wireless products are affected by CVE-2022-47069, a heap-buffer-overflow in p7zip 16.02 ZIP processing. The advisory was published on 2025-02-11 and revised on 2025-05-06 for typo fixes only. Siemens recommends updating affected products to V3.0.0 or later.
CVE-2022-39842 is a Linux kernel vulnerability that Siemens and CISA identified in multiple SCALANCE wireless products. The issue is in pxa3xx_gcu_write and involves a type conflict on the count parameter that can bypass a size check and potentially lead to heap overflow behavior. The advisory notes an important caveat: the original discoverer disputes whether the overflow can actually occur, so exploitat [truncated]
CVE-2022-22128 is a critical Siemens Opcenter Intelligence issue involving path traversal in an internal file transfer service. According to the advisory metadata, successful exploitation could allow remote code execution. The CVSS vector indicates network reachability with no privileges or user interaction required, and high impact to confidentiality, integrity, and availability. Siemens advises updating [truncated]
A vulnerability in the vsock/virtio transport layer of the Linux kernel could allow a local attacker to cause a denial-of-service condition. The flaw occurs when the virtio transport changes during packet processing, potentially leading to improper packet handling. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The vulnerability requires local [truncated]
This CVE addresses a race condition in the Linux kernel's Device Mapper (dm) thin provisioning subsystem. The vulnerability exists in the `get_first_thin` function, which previously used a non-RCU-safe list operation that could lead to use-after-free conditions during concurrent access. The fix converts this to use RCU-safe list traversal primitives, preventing potential system instability or denial of se [truncated]
CVE-2024-57929 is a double-free vulnerability in the Linux kernel's device-mapper (dm) array subsystem, specifically within the `dm_array_cursor_end()` function. The flaw occurs when `dm_bm_read_lock()` fails due to locking or checksum errors, implicitly releasing the faulty block while leaving an invalid pointer. The `dm_array_cursor` incorrectly caches this invalid pointer, leading to a double release w [truncated]
This CVE addresses a null-pointer dereference vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) subsystem, specifically within the `cookie_hmac_alg` sysctl handler. The flaw occurs when the kernel code accesses `current->nsproxy` to obtain network namespace information, which can be NULL when the current task is exiting—such as during `acct(2)` system calls as detected by syz [truncated]
A null-pointer dereference vulnerability exists in the Linux kernel's SCTP (Stream Control Transmission Protocol) sysctl implementation for the `auth_enable` parameter. The flaw occurs when the kernel accesses `current->nsproxy` to obtain network namespace information during sysctl read/write operations. In specific scenarios—such as when a task is exiting—`current->nsproxy` can be NULL, causing an Oops ( [truncated]
A vulnerability in the Linux kernel's AF_PACKET subsystem allows local attackers to trigger a kernel crash (denial of service) when using the MSG_PEEK flag with VLAN-tagged packets. The flaw exists in vlan_get_tci() which incorrectly modifies socket buffer (skb) state during peek operations, causing skb_under_panic when multiple CPUs access the same skb. The vulnerability was discovered by syzbot and affe [truncated]
A vulnerability in the Linux kernel's af_packet subsystem allows local attackers to trigger a kernel crash (denial of service) when using the MSG_PEEK flag with packet socket operations. The flaw exists in vlan_get_protocol_dgram(), which incorrectly modifies socket buffer (skb) state during peek operations, leading to skb_under_panic and a kernel BUG assertion. This vulnerability was discovered by syzbot [truncated]
CVE-2024-56841 is a high-severity LDAP injection vulnerability in Siemens Mendix LDAP that allows unauthenticated remote attackers to bypass username verification. Published January 14, 2025, this vulnerability affects the Mendix LDAP module and was disclosed through coordinated CISA and Siemens advisories. The CVSS 3.1 score of 7.4 reflects network attack vector, high attack complexity, no privileges req [truncated]
CVE-2024-53649 is a path traversal vulnerability in Siemens SIPROTEC 5 protective relay devices that allows authenticated remote attackers to read arbitrary files from the device filesystem. The vulnerability stems from improper path limitation in the embedded web server. Published on January 14, 2025, this vulnerability affects 43 distinct SIPROTEC 5 product variants across multiple device families inclu [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability in the web interface of Siemens SIMATIC S7-1200 CPUs allows unauthenticated attackers to change CPU mode by tricking authenticated users into clicking malicious links. The vulnerability was published on January 14, 2025, and affects 48 product variants across standard SIMATIC and SIPLUS product lines. Siemens has released firmware version 4.7 or later to a [truncated]
A reflected cross-site scripting (XSS) vulnerability in Siemens Industrial Edge Management OS (IEM-OS) could allow attackers to extract sensitive information by tricking users into accessing malicious links. Published January 14, 2025, this MEDIUM severity issue (CVSS 4.7) affects the IEM-OS platform with no patch planned; Siemens recommends migrating to Industrial Edge Management Virtual (IEM-V) as the r [truncated]
A critical heap-based buffer overflow vulnerability in Siemens' integrated User Management Component (UMC) affects multiple industrial automation products. The flaw allows unauthenticated remote attackers to execute arbitrary code with a CVSS 3.1 score of 9.8. The vulnerability was disclosed on December 16, 2024, with vendor fixes released across multiple product lines through January 2026.
CVE-2024-54095 is a high-severity integer underflow vulnerability in Siemens Solid Edge SE2024, published December 10, 2024. The flaw exists in the application's parsing of PAR (part) files, where specially crafted input can trigger an integer underflow condition. Successful exploitation allows arbitrary code execution within the context of the current process, with a CVSS 3.1 score of 7.8 (HIGH). The att [truncated]
A heap-based buffer overflow vulnerability exists in Siemens Solid Edge SE2024 when parsing specially crafted PAR (part) files. An attacker can exploit this flaw to execute arbitrary code within the context of the current process. The vulnerability requires local access and user interaction, as the victim must open a malicious file. Siemens has released V224.0 Update 5 to address this issue.
A heap-based buffer overflow vulnerability in Siemens Solid Edge SE2024 allows code execution when parsing malicious ASM files. Published December 10, 2024, this HIGH severity issue (CVSS 7.8) requires local access and user interaction to exploit. Siemens has released V224.0 Update 5 to address the vulnerability.
CVE-2024-54091 is a high-severity memory-corruption issue in Siemens Solid Edge affecting SE2024 and SE2025. According to the CISA CSAF advisory and Siemens security advisory, the flaw is an out-of-bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted X_T file. A successful attack could allow code execution in the context of the current process. Siemens published f [truncated]
CVE-2024-54005 is a medium-severity XML External Entity (XXE) vulnerability in the PDMS/E3D Engineering Interface of Siemens COMOS, published on December 10, 2024. The flaw allows attackers to extract files from known locations on user systems or accessible network folders by injecting malicious data into the communication channel between systems. The vulnerability affects multiple COMOS versions: V10.3, [truncated]
A medium-severity physical-access vulnerability in Siemens CPCI85 Central Processing/Communication devices allows attackers with hardware-level access to intercept secure element authentication credentials via an unencrypted SPI bus, enabling decryption of all encrypted firmware updates.
CVE-2024-52574 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. Published on December 10, 2024, and last modified on May 6, 2025, this vulnerability was reported throu [truncated]
CVE-2024-52573 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw exists in the parsing of specially crafted WRL (VRML) files and can lead to arbitrary code execution in the context of the current process. The vulnerability was disclosed on December 10, 2024, and was reported through the Zero Day Initiative ( [truncated]
CVE-2024-52572 is a stack-based buffer overflow vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The vulnerability exists in the parsing of specially crafted WRL (VRML) files and can allow an attacker to execute arbitrary code in the context of the current process. This vulnerability was disclosed through the Zero Day Initiative (ZDI-CAN-24486) and publi [truncated]
CVE-2024-52571 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw exists in the parsing of specially crafted WRL (VRML) files and can lead to arbitrary code execution in the context of the current process. The vulnerability was disclosed via CISA ICS Advisory ICSA-24-347-09 on December 10, 2024, with Siemens [truncated]
CVE-2024-52570 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw exists in the parsing of specially crafted WRL (VRML) files, which can trigger memory corruption and allow an attacker to execute arbitrary code within the context of the current process. This vulnerability was disclosed on December 10, 2024, a [truncated]
CVE-2024-52569 is an out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw occurs when parsing specially crafted WRL (VRML) files, which could allow an attacker to execute arbitrary code in the context of the current process. This vulnerability was disclosed on December 10, 2024, and carries a CVSS 3.1 score of 7.8 (HIGH severity) [truncated]
A use-after-free vulnerability in Siemens Teamcenter Visualization allows code execution when parsing malicious WRL files. The flaw was disclosed on December 10, 2024, and affects four product versions. Siemens has released security updates for all affected versions.