PatchSiren

siemens CVE debriefs · Page 50

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2024-11-12

CVE-2024-28882

CVE-2024-28882 is a medium-severity issue published by CISA on 2025-03-11 for Siemens SINEMA Remote Connect Client. The advisory text states that OpenVPN versions 2.6.0 through 2.6.10, when used in a server role, can accept multiple exit notifications from authenticated clients and extend the validity of a closing session. Siemens lists an update to V3.2 SP3 or later as the remediation.

MEDIUM Siemens CVE published 2024-11-12

CVE-2024-26306

CVE-2024-26306 affects multiple Siemens SCALANCE WAB/WAM/WUB/WUM models when iPerf3 before 3.17 is used with OpenSSL before 3.2.0 as a server with RSA authentication. The issue is a timing side channel in RSA decryption that, according to the advisory, could be sufficient for an attacker to recover credential plaintext after sending many decryption requests.

CRITICAL Siemens CVE published 2024-11-12

CVE-2023-52389

A critical integer overflow vulnerability in POCO C++ Libraries' UTF32Encoding component affects Siemens SINEC INS. The flaw in UTF32Encoding.cpp allows Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() to return negative integers when processing UTF-32 byte sequences evaluating to 0x80000000 or higher, leading to stack buffer overflow. This vulnerability was published on November 12, 2024, w [truncated]

HIGH Siemens CVE published 2024-11-12

CVE-2023-50868

CVE-2023-50868 is a HIGH severity (CVSS 7.5) denial-of-service vulnerability affecting Siemens SINEC INS. The issue stems from the Closest Encloser Proof mechanism in DNSSEC NSEC3 (RFC 5155) when RFC 9276 guidance is not followed. Remote attackers can exploit this via DNSSEC responses in a random subdomain attack, forcing the target to perform thousands of SHA-1 hash iterations and causing excessive CPU c [truncated]

HIGH Siemens CVE published 2024-11-12

CVE-2023-50387

This debrief provides an analysis of CVE-2023-50387, a vulnerability in the DNS protocol that allows remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, known as the 'KeyTrap' issue. The vulnerability arises when a zone has many DNSKEY and RRSIG records, and the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG [truncated]

HIGH Siemens CVE published 2024-11-12

CVE-2023-49441

An integer overflow vulnerability in dnsmasq 2.9's forward_query function affects 26 Siemens SCALANCE and RUGGEDCOM router products. The flaw, published November 12, 2024, carries a HIGH severity CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating network-based attackers can trigger denial of service without authentication. Siemens has released firmware updates to address this issue.

HIGH Siemens CVE published 2024-11-05

CVE-2024-50131

A vulnerability in the Linux kernel's tracing subsystem could allow a local attacker to cause a buffer overflow condition. The issue stems from improper validation of event length when the string length equals the maximum buffer length, leaving no space for the NULL terminating character. This has been resolved in the Linux kernel by adding a check that returns failure when this condition is detected. Sie [truncated]

HIGH Siemens CVE published 2024-10-23

CVE-2024-47904

A local privilege escalation vulnerability exists in Siemens InterMesh subscriber devices due to a SUID binary that allows authenticated local attackers to execute arbitrary commands with root privileges. The vulnerability was disclosed on October 23, 2024, with a revision on May 6, 2025, to correct typos. The affected products are the InterMesh 7177 Hybrid 2.0 Subscriber and InterMesh 7707 Fire Subscribe [truncated]

MEDIUM Siemens CVE published 2024-10-23

CVE-2024-47903

CVE-2024-47903 is a medium-severity vulnerability (CVSS 5.8) affecting Siemens InterMesh subscriber devices, published on 2024-10-23 and last modified on 2025-05-06. The vulnerability allows an attacker to write arbitrary files to the web server's DocumentRoot directory on affected devices, potentially enabling web defacement, malware hosting, or further compromise of the device. The issue stems from insu [truncated]

HIGH Siemens CVE published 2024-10-23

CVE-2024-47902

CVE-2024-47902 is a HIGH severity vulnerability (CVSS 7.2) affecting Siemens InterMesh subscriber devices. The web server on affected devices fails to authenticate GET requests that execute operating system-level commands such as `ping`, allowing unauthenticated remote attackers to execute arbitrary OS commands. The vulnerability was published on October 23, 2024, with a revision on May 6, 2025. Two produ [truncated]

CRITICAL Siemens CVE published 2024-10-23

CVE-2024-47901

A critical vulnerability in Siemens InterMesh subscriber devices allows unauthenticated remote attackers to execute arbitrary code with root privileges. The web server fails to sanitize input parameters in specific GET requests, enabling operating system-level code execution. When combined with CVE-2024-47902, CVE-2024-47903, and CVE-2024-47904, this vulnerability chain results in complete system compromi [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2026-27661

CVE-2026-27661 is a medium-severity information disclosure vulnerability affecting Siemens SINEC Security Monitor. The vulnerability was disclosed on October 8, 2024, and subsequently assigned CVE identifier on March 10, 2026, with the advisory updated on March 12, 2026. The affected application leaks confidential information in metadata and files, including contributor information and email addresses, on [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-53242

CVE-2024-53242 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was disclosed on December 10, 2024, and carries a CVSS 3.1 score of 7.8 (HIGH). Siemens has [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-53041

CVE-2024-53041 is a stack-based buffer overflow vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw exists in the parsing of specially crafted WRL (VRML) files, which can trigger memory corruption and allow arbitrary code execution within the context of the current process. This vulnerability was reported through the Zero Day Initiative (ZDI-CAN-25000) an [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-47565

CVE-2024-47565 is a medium-severity input validation vulnerability in Siemens SINEC Security Monitor, published 2024-10-08. The affected application fails to properly validate that user input complies with a list of allowed values, allowing an authenticated remote attacker to compromise configuration integrity. The vulnerability has a CVSS 3.1 score of 4.3 (MEDIUM) with vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/ [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-47563

CVE-2024-47563 is a path traversal vulnerability in Siemens SINEC Security Monitor that allows unauthenticated remote attackers to create files outside intended directories via a CSR file creation endpoint. The vulnerability stems from improper validation of file paths supplied to this endpoint, enabling attackers to compromise file integrity in writable directories. Published October 8, 2024, this medium [truncated]

CRITICAL Siemens CVE published 2024-10-08

CVE-2024-47553

A critical command injection vulnerability in Siemens SINEC Security Monitor allows authenticated remote attackers with low privileges to escalate to root-level code execution on the underlying operating system. The flaw stems from improper input validation in the `ssmctl-client` command. CISA published this advisory on October 8, 2024, with subsequent republications through March 12, 2026 to incorporate [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-47196

CVE-2024-47196 is a local privilege escalation vulnerability in Siemens ModelSim and Questa simulation tools. The vsimk.exe executable loads a specific Tcl file from the current working directory, allowing an authenticated local attacker to inject arbitrary code when administrators or elevated processes launch the application from user-writable directories. Published October 8, 2024, and last modified May [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-47195

CVE-2024-47195 is a local privilege escalation vulnerability in Siemens ModelSim and Questa, published 2024-10-08. The issue stems from gdb.exe loading a specific executable from the current working directory, enabling authenticated local attackers to inject arbitrary code when administrators launch gdb.exe from user-writable directories. With CVSS 6.7 (Medium), this requires local access, low privileges, [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-47194

CVE-2024-47194 is a DLL search order hijacking vulnerability in Siemens ModelSim and Questa simulation tools. The vish2.exe executable loads a specific DLL from the current working directory, enabling authenticated local attackers to escalate privileges when administrators launch the application from user-writable directories. Published October 8, 2024, this medium-severity issue (CVSS 6.7) requires local [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-47046

A memory corruption vulnerability exists in Siemens Simcenter Femap when parsing specially crafted BDF (Bulk Data File) files. The flaw, published December 10, 2024, could allow an attacker to execute arbitrary code within the context of the current process. The vulnerability affects multiple versions: V2306, V2401, and V2406. Siemens has released a vendor fix for V2406 users through the Femap 2406 Nastra [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-46887

CVE-2024-46887 is a medium-severity information disclosure vulnerability affecting 80 Siemens SIMATIC S7-1500 series CPU products, including Drive Controllers, ET 200SP variants, and ET 200pro units. Published on October 8, 2024, and last modified on October 14, 2025, this vulnerability stems from improper authentication on the '/ClientArea/RuntimeInfoData.mwsl' web server endpoint. An unauthenticated rem [truncated]

MEDIUM Siemens CVE published 2024-10-08

CVE-2024-46886

CVE-2024-46886 is a medium-severity (CVSS 4.7) open redirect vulnerability in the web server of Siemens SIMATIC industrial controllers. The web server fails to properly validate input used for user redirection, allowing an attacker to craft malicious links that redirect legitimate users to attacker-chosen URLs. Successful exploitation requires user interaction—the victim must actively click on an attacker [truncated]

LOW Siemens CVE published 2024-10-08

CVE-2024-45476

A null pointer dereference vulnerability exists in Siemens Teamcenter Visualization when parsing specially crafted WRL (VRML) files. An attacker can trigger an application crash by convincing a user to open a malicious WRL file, resulting in a denial-of-service condition. The vulnerability requires local access and user interaction, with a CVSS 3.1 score of 3.3 (Low severity). Siemens has released patched [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-45475

CVE-2024-45475 is a high-severity memory corruption vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs during parsing of specially crafted WRL (VRML) files, which can lead to arbitrary code execution in the context of the current process when combined with other vulnerabilities. Published by CISA on December 10, 2024, and last modified on May 6, 2 [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-45474

CVE-2024-45474 is a memory corruption vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs during parsing of specially crafted WRL (VRML) files, which could enable code execution in the context of the current process when chained with other vulnerabilities. Published by CISA on December 10, 2024, and last modified on May 6, 2025, this vulnerability [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-45473

CVE-2024-45473 is a high-severity memory corruption vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs during parsing of specially crafted WRL (VRML) files, which could enable code execution in the context of the current process when chained with other vulnerabilities. Published by CISA on December 10, 2024, and last modified on May 6, 2025, this [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-45472

A memory corruption vulnerability in Siemens Teamcenter Visualization allows code execution when parsing malicious WRL files. The flaw, published 2024-12-10 and last modified 2025-05-06, carries a CVSS 3.1 score of 7.8 (HIGH). Affected versions include V14.2, V14.3, and V2312. Siemens has released patched versions, and CISA recommends updating immediately while avoiding untrusted WRL files.

HIGH Siemens CVE published 2024-10-08

CVE-2024-45471

CVE-2024-45471 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw exists in the parsing of specially crafted WRL (VRML) files, which can trigger memory corruption and allow an attacker to execute arbitrary code within the context of the current process. This vulnerability requires local access and user interaction, [truncated]

HIGH Siemens CVE published 2024-10-08

CVE-2024-45470

CVE-2024-45470 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw exists in the parsing of specially crafted WRL (VRML) files, which can trigger memory corruption and allow an attacker to execute arbitrary code within the context of the current process. This vulnerability requires local access and user interaction, [truncated]