These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A local privilege escalation vulnerability in Siemens SINEC NMS allows authenticated users to execute operating system commands with SYSTEM-level privileges. The affected application runs a subset of services as NT AUTHORITY SYSTEM, creating an attack surface where a local attacker with existing access can elevate privileges to execute arbitrary OS commands. This vulnerability requires local access and lo [truncated]
A remote code execution vulnerability in .NET and Visual Studio affects Siemens INTRALOG WMS, published 2024-08-13. The vulnerability could allow arbitrary code execution on INTRALOG WMS application servers. Exploitation requires the attacker to be located within the controlled network of the INTRALOG WMS deployment, limiting the attack surface to insider threats or compromised network segments rather tha [truncated]
CVE-2023-5870 is a medium-severity vulnerability in PostgreSQL affecting the pg_cancel_backend role, which can signal background workers including logical replication launcher, autovacuum workers, and the autovacuum launcher. The vulnerability was published on August 13, 2024. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect only that specific [truncated]
A memory disclosure vulnerability in PostgreSQL affects Siemens SINEC NMS. The issue stems from aggregate function calls handling 'unknown'-type arguments derived from string literals without explicit type designation, which can cause excessive data output and leak portions of system memory to remote authenticated users. CISA published advisory ICSA-24-228-06 on August 13, 2024, identifying this vulnerabi [truncated]
CVE-2023-5180 is a high-severity vulnerability in Open Design Alliance Drawings SDK versions prior to 2024.12, affecting Siemens COMOS. The flaw stems from improper validation of the number of sectors used by the File Allocation Table (FAT) structure when parsing crafted DGN files. A corrupted value in this field leads to an out-of-bounds write condition, which an attacker can leverage to achieve arbitrar [truncated]
CVE-2023-46589 is an improper input validation vulnerability in Apache Tomcat that affects multiple versions across the 8.5, 9.0, 10.1, and 11.0 release lines. The vulnerability stems from incorrect parsing of HTTP trailer headers, where a trailer header exceeding the configured size limit can cause Tomcat to misinterpret a single HTTP request as multiple separate requests. This parsing error creates cond [truncated]
CVE-2023-45648 is an improper input validation vulnerability in Apache Tomcat affecting versions 11.0.0-M1 through 11.0.0-M11, 10.1.0-M1 through 10.1.13, 9.0.0-M1 through 9.0.81, and 8.5.0 through 8.5.93. The vulnerability stems from incorrect parsing of HTTP trailer headers, where a specially crafted invalid trailer header could cause Tomcat to treat a single request as multiple requests. This creates a [truncated]
CVE-2023-42795 is a MEDIUM-severity (CVSS 5.3) Incomplete Cleanup vulnerability in Apache Tomcat, published 2024-08-13. The flaw affects Tomcat versions 11.0.0-M1 through 11.0.0-M11, 10.1.0-M1 through 10.1.13, 9.0.0-M1 through 9.0.80, and 8.5.0 through 8.5.93. When recycling internal objects, an error can cause Tomcat to skip portions of the recycling process, resulting in information leakage from the cur [truncated]
CVE-2023-42794 is a MEDIUM severity (CVSS 5.9) Incomplete Cleanup vulnerability in Apache Tomcat, affecting versions 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93. The issue stems from an internal fork of Commons FileUpload that included unreleased refactoring code, exposing a denial-of-service condition on Windows systems. If a web application opens a stream for an uploaded file but fails to close it, [truncated]
CVE-2023-34050 is a deserialization vulnerability in Spring AMQP affecting versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9. The vulnerability stems from insecure default configuration: when no allowed list patterns are specified for deserializable class names, all classes can be deserialized by default. This exposes applications to potential remote code execution when using SimpleMessageConverter or Serialize [truncated]
A firmware downgrade vulnerability in Siemens SICAM products allows attackers to roll back to older, vulnerable firmware versions. The flaw permits remote authenticated users or unauthenticated users with physical access to downgrade device firmware, potentially reintroducing known security vulnerabilities that were previously patched. This vulnerability affects CPCI85 Central Processing/Communication and [truncated]
A critical authentication bypass vulnerability in Siemens SICAM products allows unauthorized administrative access when auto login is enabled. The flaw permits password reset of administrative accounts without knowledge of the current password, enabling complete system compromise.
A buffer over-read vulnerability in FortiOS, affecting the Siemens RUGGEDCOM APE1808 industrial platform, may allow a remote unauthenticated attacker to crash the FGFM (FortiGate to FortiManager) daemon via a specially crafted request. Successful exploitation requires rare conditions outside the attacker's control, limiting practical exploitability. The vulnerability was disclosed in CISA ICS Advisory ICS [truncated]
A denial-of-service vulnerability in Palo Alto Networks PAN-OS software, as deployed on Siemens RUGGEDCOM APE1808 devices, enables unauthenticated attackers to reboot the firewall via a specially crafted dataplane packet. Repeated exploitation can force the device into maintenance mode, causing sustained service disruption. The vulnerability was disclosed in CISA advisory ICSA-24-193-11 on 2024-07-09 and [truncated]
A critical command injection vulnerability in Palo Alto Networks PAN-OS® affects the Siemens RUGGEDCOM APE1808 industrial platform. The vulnerability enables authenticated administrative users to execute arbitrary commands with root privileges through the management web interface. This represents a significant elevation of privilege risk, as administrative access—while requiring authentication—can be leve [truncated]
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway. The vulnerability was published on July 9, 2024, and most recently modifi [truncated]
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS via a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated exploitation attempts cause PAN-OS to enter maintenance mode. This vulnerability affects the Palo Alto Networks Virtual NGFW deployed on Siemens RUGGEDCOM APE1808 devices. The issue [truncated]
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges. This vulnerability affects the Siemens RUGGEDCOM APE1808 industrial computing platform, which runs Palo Alto Networks Virtual NGFW. The issue requires physical access to the device, limiting remote exploitation risk. The vulner [truncated]
A channel accessible by non-endpoint vulnerability (CWE-300) in Fortinet FortiOS and FortiProxy allows unauthenticated attackers with knowledge of device-specific data to spoof the identity of a downstream device in the security fabric via crafted TCP requests. This vulnerability affects Siemens RUGGEDCOM APE1808, which incorporates the affected Fortinet components. The issue was disclosed on July 9, 2024 [truncated]
CVE-2024-47570 is a medium-severity (CVSS 6.6) information disclosure vulnerability affecting Fortinet software components embedded in Siemens RUGGEDCOM APE1808 devices. The flaw, classified as CWE-532 (Insertion of Sensitive Information into Log File), was published on July 9, 2024, and last modified on January 14, 2026. The vulnerability exists in FortiOS versions 7.4.0 through 7.4.3, 7.2.0 through 7.2. [truncated]
CVE-2024-39888 is a HIGH severity vulnerability (CVSS 7.5) in Siemens Mendix Encryption Module, published July 9, 2024. The vulnerability stems from a hard-coded default EncryptionKey constant used when no individual encryption key is specified in a project. This cryptographic weakness allows attackers to decrypt any encrypted project data protected by the default key, effectively rendering the encryption [truncated]
CVE-2024-39875 is a medium-severity information disclosure vulnerability in Siemens SINEMA Remote Connect Server. Published on July 9, 2024, the flaw allows authenticated low-privilege users with the 'Manage own remote connections' permission to retrieve details about other users and their group memberships. This represents an authorization boundary violation where users can access information outside the [truncated]
A high-severity vulnerability in Siemens SINEMA Remote Connect Server allows attackers to brute-force user credentials due to missing rate limiting in the Client Communication component. The flaw, published July 9, 2024, enables network-based attackers to systematically guess credentials without account lockout protections. Siemens has released version 3.2 SP1 to address this authentication weakness.
A high-severity vulnerability in Siemens SINEMA Remote Connect Server allows credential brute-force attacks due to missing rate limiting on the web API authentication endpoint. Published July 9, 2024, this flaw enables network-based attackers to systematically guess user credentials without account lockout or throttling protections. The CVSS 3.1 score of 7.5 reflects high confidentiality impact with no in [truncated]
A broken access control vulnerability in Siemens SINEMA Remote Connect Server allows authenticated attackers with device management permissions to escalate privileges and access unauthorized participant groups. The root cause is improper separation of privileges between device settings editing and communication relation settings editing. Published July 9, 2024, with a CVSS 3.1 score of 6.3 (Medium). Sieme [truncated]
A privilege escalation vulnerability in Siemens SINEMA Remote Connect Server allows authenticated local users with user management privileges to modify accounts outside their authorized scope and escalate privileges. The issue stems from improper authorization checks when the application is configured to allow users to manage their own user accounts. Affected versions require update to V3.2 SP1 or later.
CVE-2024-39869 is a medium-severity vulnerability (CVSS 6.5) affecting Siemens SINEMA Remote Connect Server, published on 2024-07-09. The vulnerability allows an authenticated attacker to upload a crafted certificate that results in a permanent denial-of-service condition. Recovery requires manual removal of the offending certificate. The attack vector is network-based with low attack complexity, requirin [truncated]
A high-severity authentication bypass vulnerability in Siemens SINEMA Remote Connect Server allows unauthenticated attackers to access and modify device configurations for which they lack authorization. The flaw stems from improper authentication validation during specific web interface actions. Published July 9, 2024, this vulnerability carries a CVSS 3.1 score of 7.6 (HIGH severity). Siemens has release [truncated]
CVE-2024-39866 is a HIGH severity vulnerability (CVSS 8.8) in Siemens SINEMA Remote Connect Server, published July 9, 2024. The vulnerability allows an attacker with access to the backup encryption key and upload privileges to create administrative users by uploading malicious encrypted backup files. The attack vector is network-based with low attack complexity, requiring low privileges but no user intera [truncated]