These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2024-45469 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw exists in the parsing of specially crafted WRL (VRML) files, which can trigger memory corruption and allow an attacker to execute arbitrary code within the context of the current process. This vulnerability was disclosed on December 10, 2024, and carr [truncated]
A memory corruption vulnerability exists in Siemens Teamcenter Visualization when parsing specially crafted WRL (VRML) files. An attacker can exploit this flaw to execute arbitrary code within the context of the current process. The vulnerability requires local access and user interaction, with a HIGH severity CVSS 3.1 score of 7.8. Siemens has released security updates for affected versions, and CISA pub [truncated]
A memory corruption vulnerability in Siemens Teamcenter Visualization allows code execution when parsing malicious WRL files. The flaw, published December 10, 2024, carries a HIGH severity CVSS 3.1 score of 7.8. Attackers can exploit this by convincing users to open crafted WRL files, resulting in arbitrary code execution within the current process context. Siemens has released patched versions for affect [truncated]
CVE-2024-45466 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. Published by CISA on December 10, 2024, and last modified on May 6, 2025, this vulnerability requires local ac [truncated]
CVE-2024-45465 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. Published by CISA on December 10, 2024, this vulnerability requires local access and user interaction, with an [truncated]
CVE-2024-45464 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. Published by CISA on December 10, 2024, this vulnerability requires local access and user interaction, with an [truncated]
CVE-2024-45463 is a high-severity out-of-bounds read vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, and V2312. The flaw occurs when parsing specially crafted WRL (VRML) files, allowing an attacker to execute arbitrary code in the context of the current process. Published by CISA on December 10, 2024, this vulnerability requires local access and user interaction, with a [truncated]
CVE-2024-45182 is a medium-severity vulnerability (CVSS 6.5) affecting WIBU-SYSTEMS WibuKey before version 6.70, specifically in the WibuKey64.sys driver component. The vulnerability stems from an improper bounds check that allows specially crafted packets to trigger an arbitrary address read, resulting in Denial of Service conditions. This issue was disclosed on October 8, 2024, through CISA's ICS adviso [truncated]
An improper bounds check vulnerability exists in WibuKey64.sys, a kernel driver component of WIBU-SYSTEMS WibuKey software licensing protection system. The flaw, present in versions prior to 6.70, allows crafted packets to trigger an arbitrary address write, resulting in kernel memory corruption. This vulnerability affects Siemens PSS(R)SINCAL, which incorporates the vulnerable WibuKey component. The issu [truncated]
A heap-based buffer overflow vulnerability exists in Siemens Simcenter Femap when parsing specially crafted BDF (Bulk Data File) files. The vulnerability, published on December 10, 2024, allows an attacker to execute arbitrary code in the context of the current process. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, but user interaction requir [truncated]
A stack-based buffer overflow vulnerability exists in Siemens JT2Go, triggered when parsing specially crafted PDF files. Successful exploitation allows code execution in the context of the current process. The vulnerability was disclosed on October 8, 2024, with a vendor fix available in version V2406.0003 or later. CISA and Siemens have published coordinated advisories with mitigation guidance and patch information.
CVE-2024-41798 is a critical vulnerability in Siemens SENTRON 7KM PAC3200 power monitoring devices, published on October 8, 2024. The devices use only a 4-digit PIN to protect administrative access via the Modbus TCP interface, which is trivially bypassable through brute-force attacks or by sniffing the unencrypted Modbus traffic. The CVSS 3.1 score of 9.8 reflects network attackability with low complexit [truncated]
A restricted desktop environment escape vulnerability exists in the Kiosk Mode of Siemens HiMed Cockpit medical devices. An unauthenticated local attacker can exploit this flaw to break out of the restricted environment and gain access to the underlying operating system. This vulnerability affects four HiMed Cockpit models used in healthcare environments, where kiosk mode is typically deployed to limit us [truncated]
A use of uninitialized variable vulnerability exists in the Linux kernel's FOU (Foo Over UDP) implementation. The issue stems from improper initialization order where the `grc` variable may be used before being initialized. If the `fou` pointer is NULL, a `goto out` path is executed that references the uninitialized `grc` variable, potentially leading to information disclosure or denial of service conditi [truncated]
CVE-2024-45016 is a vulnerability in the Linux kernel's netem (network emulator) subsystem. The issue involves an incorrect return value when duplicate packet enqueue operations fail, which could lead to improper error handling in network traffic control operations. The vulnerability was resolved in the Linux kernel with a fix to ensure proper return values are used when duplicate enqueue fails. Siemens h [truncated]
CVE-2024-45032 is a critical authentication bypass vulnerability in Siemens Industrial Edge Management Pro and Industrial Edge Management Virtual. The affected components fail to properly validate device tokens, enabling an unauthenticated remote attacker to impersonate other devices that are onboarded to the system. This vulnerability carries a CVSS 3.1 score of 10.0 (Critical), reflecting its network at [truncated]
CVE-2024-44087 is a high-severity vulnerability in Siemens Automation License Manager affecting versions V5, V6.0, and V6.2. The flaw involves improper validation of certain fields in incoming network packets on TCP port 4410, which can be exploited by an unauthenticated remote attacker to trigger an integer overflow and crash the application. This denial-of-service condition can prevent legitimate users [truncated]
A vulnerability in Siemens SIMATIC S7-200 SMART CPU devices allows unauthenticated remote attackers to cause denial of service by sending malformed TCP packets. The flaw stems from improper handling of TCP packets with incorrect structure. Recovery requires physical intervention—unplugging and re-plugging the network cable. Siemens has stated that no fix is currently planned for this vulnerability. The af [truncated]
A session management vulnerability in Siemens SINEMA Remote Connect Server allows remote attackers to bypass multi-factor authentication (MFA) during user session establishment. The affected application fails to properly handle session establishment and invalidation, enabling MFA circumvention. Siemens has released a vendor fix in version V3.2 SP2 or later. The vulnerability carries a CVSS 3.1 score of 4. [truncated]
Siemens SINEMA Remote Connect Client logs sensitive configuration data to a file readable by all legitimate users of the underlying system. An authenticated attacker with local access can read these logs to obtain other users' configuration data, compromising confidentiality. The vulnerability was published on September 10, 2024, with a CVSS 3.1 score of 4.4 (Medium). Siemens has released a vendor fix in [truncated]
CVE-2024-41171 is a high-severity local privilege escalation vulnerability in Siemens SINUMERIK CNC systems, published 2024-09-10. Affected devices fail to properly enforce access restrictions on scripts executed with elevated privileges, allowing an authenticated local attacker to escalate privileges on the underlying system. The vulnerability affects four product variants: SINUMERIK 828D V4, SINUMERIK 8 [truncated]
A stack-based buffer overflow vulnerability exists in Siemens Tecnomatix Plant Simulation V2302 and V2404 when parsing specially crafted SPP (Plant Simulation Project) files. The flaw allows an attacker to execute arbitrary code within the context of the current process. This vulnerability requires local access and user interaction, as the victim must open a malicious SPP file. The CVSS 3.1 score of 7.8 r [truncated]
A vulnerability in the Socket.IO real-time communication framework, used by multiple Siemens industrial products, allows remote attackers to trigger an uncaught exception on the server, causing the Node.js process to terminate. This results in a denial-of-service condition. The vulnerability stems from improper exception handling when processing specially crafted Socket.IO packets. The underlying Socket.I [truncated]
A vulnerability in Siemens SIMATIC RFID Readers allows an attacker to cause an application crash and potentially disclose sensitive information by uploading a faulty certificate. The affected application does not properly handle errors during certificate upload operations, leading to a denial-of-service condition. This vulnerability affects 27 Siemens SIMATIC RFID Reader products across multiple product f [truncated]
A hidden debug configuration item in Siemens SIMATIC RFID readers could allow authenticated attackers to gain insight into internal deployment configurations. The vulnerability affects 27 SIMATIC Reader and RF communication module products across multiple regional variants (ARIB, CMIIT, ETSI, FCC). CISA published this advisory on September 10, 2024, with a revision on May 6, 2025 to fix typos. Siemens has [truncated]
CVE-2024-37993 is a medium-severity vulnerability affecting 27 Siemens SIMATIC RFID reader products. The issue stems from missing authentication on Ajax2App instance creation, allowing unauthenticated attackers to trigger denial-of-service conditions. Published September 10, 2024, and last modified May 6, 2025, this vulnerability carries a CVSS 3.1 score of 5.3. Siemens has released firmware updates addre [truncated]
A vulnerability in Siemens SIMATIC RFID readers allows an authenticated attacker to trigger an application restart by sending SNMP configuration data that exceeds character limits. The affected devices do not properly handle this error condition, resulting in denial of service. The vulnerability requires network access and administrative privileges (PR:H), with a CVSS 3.1 score of 4.9 (MEDIUM). Twenty-sev [truncated]
CVE-2024-37991 is a medium-severity information disclosure vulnerability affecting 27 Siemens SIMATIC RFID reader products. The vulnerability allows unauthenticated attackers to access service log files without proper authentication, potentially exposing sensitive operational information. The issue was disclosed on September 10, 2024, and affects multiple product families including RF610R, RF615R, RF650R, [truncated]
A medium-severity vulnerability (CVSS 6.5) in Siemens SIMATIC RFID readers allows attackers with privileged access to modify configuration files and enable unreleased features. Published September 10, 2024, this issue affects 27 Siemens SIMATIC RFID reader products including RF610R, RF615R, RF650R, RF680R, RF685R series readers, RF1140R, RF1170R, RF166C, RF185C, RF186C, RF186CI, RF188C, RF188CI, and RF360 [truncated]
A critical vulnerability in Siemens SIMATIC industrial control systems allows authenticated attackers to execute arbitrary OS commands with administrative privileges due to database servers running with elevated privileges. The vulnerability affects 11 products across the SIMATIC product line including BATCH, PCS 7, WinCC, Process Historian, and Information Server versions. Siemens has released patches fo [truncated]