These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Triangle Microworks TMW IEC 61850 Client source code libraries before version 12.2.0 contain a buffer overflow vulnerability due to missing buffer size checks when processing received messages. This vulnerability can cause crashes leading to denial of service conditions. The vulnerability affects Siemens industrial control products that incorporate the vulnerable third-party library, including ET85 Ethern [truncated]
A critical heap-based buffer overflow vulnerability in Siemens' integrated User Management Component (UMC) affects multiple industrial software products, including Opcenter Quality, Opcenter RDnL, SIMATIC PCS neo, SINEC NMS, SINEMA Remote Connect Client, and Totally Integrated Automation Portal (TIA Portal) versions V16-V19. The vulnerability, published September 10, 2024, and last modified October 14, 20 [truncated]
CVE-2024-32006 is a session management vulnerability in Siemens SINEMA Remote Connect Client where user sessions are not expired upon system reboot if the user has not explicitly logged out. This flaw could allow an attacker to bypass Multi-Factor Authentication (MFA) protections. The vulnerability stems from improper session lifecycle management, where authentication state persists across reboots rather [truncated]
CVE-2023-49069 is a medium-severity (CVSS 5.3) authentication vulnerability in Siemens Mendix Runtime affecting versions V8, V9, V10, V10.6, and V10.12. The flaw involves an observable response discrepancy during username validation that allows unauthenticated remote attackers to enumerate valid usernames through differential responses. Published on September 10, 2024, this vulnerability was disclosed thr [truncated]
A NULL dereference vulnerability in the web server of multiple Siemens SIMATIC and related industrial control products allows unauthenticated remote attackers to cause denial of service by sending crafted HTTP requests with the Expect header. The vulnerability stems from improper error handling when processing certain Expect header values, leading to a NULL pointer dereference that crashes the web server [truncated]
A vulnerability in the web server of multiple Siemens SIMATIC and SIPLUS industrial communication processors allows a remote attacker with elevated privileges to cause a denial of service condition by improperly handling shutdown or reboot requests, leading to resource cleanup issues.
A medium-severity denial-of-service vulnerability in Siemens SIMATIC and related industrial communication products. The web server component fails to properly handle certain requests, triggering a watchdog timeout that leads to pointer cleanup and system unavailability. A remote attacker can exploit this without authentication to disrupt industrial control operations.
CVE-2020-15782 is a critical memory protection bypass issue in Siemens SIMATIC S7-1200 and S7-1500 CPU products. In the supplied CSAF advisory, the affected deployment context is FESTO Didactic CP, MPS 200, and MPS 400 systems when Siemens Simatic S7-1500 / ET200SP firmware below V2.9.2 is installed. The safest response is to update to V2.9.2 or higher; where updates are not available, use the vendor coun [truncated]
CVE-2024-43858 is a HIGH severity (CVSS 7.8) array-index-out-of-bounds vulnerability in the JFS (Journaled File System) implementation of the Linux kernel, specifically within the `diFree` function. The vulnerability was resolved in the upstream Linux kernel. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system. The vulnerab [truncated]
A race condition vulnerability exists in the Linux kernel's DMA management code, specifically within the dmam_free_coherent() function. The issue stems from an incorrect call order where the DMA allocation is freed before the corresponding devres tracking entry is destroyed. This creates a window where a concurrent task could allocate the same virtual address and add it to the devres list, resulting in du [truncated]
A use-after-free vulnerability exists in the Linux kernel's LED trigger subsystem. The flaw occurs in the deactivation path where sysfs attributes are unregistered after the deactivate() callback is invoked. Since trigger-specific data is typically allocated by activate() and freed by deactivate(), this ordering creates a race window where sysfs attribute show/store functions may access freed memory. The [truncated]
A vulnerability in the Linux kernel's UDF (Universal Disk Format) filesystem implementation could allow a local attacker to cause a denial of service condition. The issue stems from improper handling of corrupted block bitmap buffers in the UDF filesystem driver. When processing a malformed UDF filesystem image, the kernel may use a corrupted block bitmap buffer, leading to potential system instability or [truncated]
A vulnerability in the Linux kernel's ext4 filesystem implementation could allow a local attacker to cause a denial of service condition. The issue stems from improper handling of directory blocks where the first directory block could be a hole, leading to potential filesystem corruption or system instability. This vulnerability was resolved by ensuring the first directory block is properly allocated and not a hole.
A vulnerability in the Linux kernel's NVMe PCI driver could allow a local, privileged attacker to cause a denial of service (DoS) condition. The issue stems from a missing condition check in nvme_unmap_data() that fails to verify the existence of mapped data before dereferencing, potentially leading to a NULL pointer dereference. The vulnerability was resolved by ensuring nvme_unmap_data() applies the sam [truncated]
CVE-2024-42272 is a medium-severity vulnerability (CVSS 5.5) affecting the Linux kernel's traffic control subsystem, specifically in the `act_ct` (connection tracking action) scheduler. The issue involves improper handling of padding in the `struct zones_ht_key` structure, which can lead to memory safety issues. This vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP [truncated]
CVE-2024-41978 is a medium-severity vulnerability affecting 24 Siemens industrial router products, including SCALANCE M-series routers and RUGGEDCOM RM1224 devices. Published on August 13, 2024, the issue stems from sensitive 2FA token generation information being written to log files. An authenticated remote attacker with access to these logs could extract sufficient data to forge 2FA tokens for other us [truncated]
CVE-2024-41977 is a HIGH severity (CVSS 7.1) session isolation vulnerability in Siemens industrial routers. Published 2024-08-13, the flaw affects 24 Siemens SCALANCE and RUGGEDCOM router models where the web server component fails to properly enforce isolation between user sessions. An authenticated remote attacker can exploit this weakness to escalate privileges on affected devices. The vulnerability re [truncated]
CVE-2024-41976 is a high-severity vulnerability affecting 24 Siemens industrial router products, including SCALANCE M-series routers and RUGGEDCOM RM1224 devices. Published on August 13, 2024, this vulnerability stems from improper input validation in specific VPN configuration fields. An authenticated remote attacker can exploit this weakness to execute arbitrary code on affected devices. The CVSS 3.1 sc [truncated]
CVE-2024-41941 is a medium-severity authorization bypass vulnerability in Siemens SINEC NMS, published on August 13, 2024. The affected application fails to properly enforce authorization checks, allowing an authenticated attacker to bypass these checks and modify application settings without proper authorization. The vulnerability has a CVSS 3.1 score of 4.3 (MEDIUM severity) with the vector CVSS:3.1/AV: [truncated]
A critical vulnerability in Siemens SINEC NMS allows authenticated attackers to execute OS commands with elevated privileges due to improper input validation on a privileged command queue. Published August 13, 2024, this vulnerability carries a CVSS 9.1 score and requires network access but no user interaction. The attack complexity is low, though the attacker must have high privileges. The vendor has rel [truncated]
CVE-2024-41939 is a high-severity authorization bypass vulnerability in Siemens SINEC NMS, published on 2024-08-13. The affected application fails to properly enforce authorization checks, allowing an authenticated attacker to bypass these controls and elevate privileges within the application. With a CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), this vulnerability presents significant risk [truncated]
A path traversal vulnerability in the importCertificate function of the SINEC NMS Control web application allows authenticated attackers to delete arbitrary certificate files on the installation drive. The vulnerability was published on August 13, 2024, with a CVSS 3.1 score of 5.5 (Medium severity). Authentication is required for exploitation, limiting the attack surface to users with valid credentials. [truncated]
CVE-2024-41908 is a high-severity out-of-bounds read vulnerability in Siemens NX, a widely used computer-aided design (CAD) and manufacturing software. The flaw exists in the application's parsing of specially crafted PRT (part) files, which are native Siemens NX file formats. When exploited, this vulnerability can cause application crashes or potentially enable code execution within the context of the cu [truncated]
CVE-2024-41907 is a medium-severity vulnerability affecting Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0), published on 2024-08-13. The web server component lacks general HTTP security headers, increasing susceptibility to clickjacking attacks where an attacker could trick users into interacting with hidden interface elements. The CVSS 3.1 score of 4.2 (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N) reflects [truncated]
A cache handling vulnerability in Siemens SINEC Traffic Analyzer web service could allow attackers to read and modify locally cached data. The issue stems from improper handling of cacheable HTTP responses. Siemens has released version 2.0 to address this vulnerability.
CVE-2024-41905 is a medium-severity access control vulnerability in Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0), published 2024-08-13. The affected application lacks access controls for file access, allowing an authenticated attacker with low privileges to obtain sensitive information. The CVSS 3.1 score of 6.8 reflects network attack vector, high attack complexity, low privileges required, no use [truncated]
CVE-2024-41904 is a HIGH severity (CVSS 7.5) authentication weakness in Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0), published 2024-08-13. The affected application fails to enforce restrictions on excessive authentication attempts, enabling unauthenticated attackers to conduct brute force attacks against legitimate user credentials or keys. The vulnerability is network-exploitable with low attack [truncated]
A medium-severity authentication weakness in Siemens Location Intelligence family products allows brute-force attacks due to insufficient password policy enforcement. Published 2024-08-13 by CISA and Siemens.
CVE-2024-41682 is a medium-severity authentication weakness in Siemens Location Intelligence family products, published August 13, 2024. The vulnerability stems from insufficient enforcement of rate limiting on authentication attempts, enabling unauthenticated remote attackers to conduct brute force attacks against legitimate user credentials. The CVSS 3.1 score of 5.3 reflects network accessibility with [truncated]
A medium-severity vulnerability in Siemens Location Intelligence family products allows unauthenticated on-path attackers to read and modify data due to weak default cipher configurations. Published August 13, 2024, this issue affects the web server component of affected products. The attack requires adjacent network access, high attack complexity, and user interaction, but successful exploitation enables [truncated]