PatchSiren

siemens CVE debriefs · Page 54

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2024-07-09

CVE-2024-39865

A path traversal vulnerability in Siemens SINEMA Remote Connect Server allows authenticated attackers with backup encryption key access to achieve remote code execution via malicious backup file restoration.

HIGH Siemens CVE published 2024-07-09

CVE-2024-39675

CVE-2024-39675 is a HIGH severity vulnerability (CVSS 8.8) affecting Siemens RUGGEDCOM serial industrial networking devices. In certain configurations, affected products incorrectly enable the Modbus service on non-managed VLANs, exposing serial devices to unauthorized network access. The vulnerability was published on 2024-07-09 and last modified on 2025-08-12, when CISA expanded the advisory to include [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-39571

CVE-2024-39571 is a high-severity command injection vulnerability in Siemens SINEMA Remote Connect Server, published July 9, 2024. The vulnerability stems from missing server-side input sanitization when loading SNMP configurations, allowing an authenticated attacker with SNMP configuration modification rights to execute arbitrary code with root privileges. The CVSS 3.1 score of 8.8 reflects network attac [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-39570

A command injection vulnerability in Siemens SINEMA Remote Connect Server allows authenticated attackers to execute arbitrary code with root privileges. The flaw stems from missing server-side input sanitization when loading VxLAN configurations. Published July 9, 2024, this HIGH severity issue (CVSS 8.8) requires authentication but poses significant risk given the root-level code execution capability.

HIGH Siemens CVE published 2024-07-09

CVE-2024-39568

CVE-2024-39568 is a high-severity command injection vulnerability in Siemens SINEMA Remote Connect Client, published 2024-07-09. The flaw exists in the system service due to missing server-side input sanitization when loading proxy configurations. An authenticated local attacker can exploit this to execute arbitrary code with system privileges. The CVSS 3.1 score of 7.8 reflects high impacts to confidenti [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-39567

CVE-2024-39567 is a high-severity command injection vulnerability in Siemens SINEMA Remote Connect Client, published on July 9, 2024. The vulnerability exists in the system service due to missing server-side input sanitization when loading VPN configurations. An authenticated local attacker can exploit this flaw to execute arbitrary code with system privileges. The CVSS 3.1 score of 7.8 reflects high impa [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-38867

Siemens SIPROTEC 5 devices support weak TLS ciphers on ports 443/tcp (web), 4443/tcp (DIGSI 5), and configurable syslog-over-TLS ports. An attacker in a man-in-the-middle position could exploit this to decrypt traffic. The vulnerability was published on 2024-07-09 and last modified on 2025-11-11, when fixes were added for additional product variants (SIPROTEC 5 7SA82, 7SD82, 7SL82, and 7UT82 with CP100). [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-38278

A medium-severity vulnerability in Siemens RUGGEDCOM industrial network devices allows remote shell access when IP forwarding is enabled. The flaw causes certain remote services to become accessible on non-managed VLANs even when not intentionally activated, exposing affected systems to unauthorized remote access. Published July 9, 2024, with advisory updates continuing through August 12, 2025.

HIGH Siemens CVE published 2024-07-09

CVE-2024-37997

A stack-based buffer overflow vulnerability exists in Siemens JT2Go and Teamcenter Visualization products when parsing specially crafted XML files. An attacker can exploit this by convincing a user to open a malicious XML file, resulting in arbitrary code execution within the context of the current process. The vulnerability was disclosed on October 8, 2024, and carries a HIGH severity CVSS 3.1 score of 7 [truncated]

LOW Siemens CVE published 2024-07-09

CVE-2024-37996

CVE-2024-37996 is a null pointer dereference vulnerability in Siemens JT2Go and Teamcenter Visualization products, published on 2024-10-08 and last modified on 2025-05-06. The vulnerability exists in the XML parsing functionality of affected applications, where specially crafted XML files can trigger a null pointer dereference leading to application crash and denial of service. The CVSS 3.1 score of 3.3 ( [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-36505

CVE-2024-36505 is an improper access control vulnerability (CWE-284) affecting FortiOS versions 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14, and 6.4.x. The vulnerability was published on July 9, 2024, and most recently modified on January 14, 2026. It was added to the CISA ICS advisory ICSA-24-193-02 on September 10, 2024, as documented in the revision history. Siemens RUGGEDCOM APE180 [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-33654

CVE-2024-33654 is a high-severity vulnerability in Siemens Simcenter Femap, published on 2024-07-09. The vulnerability involves an out-of-bounds read past the end of an allocated structure when parsing specially crafted BMP files, which could allow an attacker to execute code in the context of the current process. The CVSS 3.1 score is 7.8 (HIGH), with a vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indi [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-33653

CVE-2024-33653 is a high-severity vulnerability in Siemens Simcenter Femap, published on 2024-07-09. The vulnerability stems from an out-of-bounds read past the end of an allocated structure when parsing specially crafted BMP files, which could allow an attacker to execute arbitrary code in the context of the current process. The CVSS v3.1 score of 7.8 reflects high impacts to confidentiality, integrity, [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-33510

CVE-2024-33510 is a medium-severity injection vulnerability (CWE-74) affecting Fortinet SSL-VPN web interfaces, with impact to Siemens RUGGEDCOM APE1808 deployments. Published 2024-07-09 and last modified 2026-01-14, this vulnerability stems from improper neutralization of special elements in output used by downstream components. The flaw exists in FortiOS versions 7.4.3 and below, 7.2.8 and below, and 7. [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-30321

A medium-severity information disclosure vulnerability in Siemens SIMATIC WinCC and PCS 7 products allows unauthenticated remote attackers to retrieve privileged information including user credentials through improper handling of web application requests. The vulnerability affects six product variants across the SIMATIC WinCC and PCS 7 product lines, with vendor fixes available for all affected versions a [truncated]

LOW Siemens CVE published 2024-07-09

CVE-2024-26015

An incorrect parsing of numbers with different radices vulnerability (CWE-1389) in Fortinet FortiProxy and FortiOS IP address validation features may allow an unauthenticated attacker to bypass IP blocklist protections via crafted requests. This vulnerability affects Siemens RUGGEDCOM APE1808, which incorporates the affected Fortinet components. The issue stems from improper handling of numeric values wit [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-26010

CVE-2024-26010 is a stack-based buffer overflow vulnerability affecting multiple Fortinet products, including FortiOS, FortiProxy, FortiPAM, FortiWeb, FortiAuthenticator, and FortiSwitchManager. The vulnerability was published on July 9, 2024, and carries a HIGH severity CVSS score of 7.5. Siemens RUGGEDCOM APE1808, an industrial edge computing platform that incorporates Fortinet NGFW technology, is affec [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-26008

CVE-2024-26008 is a medium-severity vulnerability (CVSS 5.3) affecting the Fortinet FortiGate Management Protocol (fgfm) daemon. The vulnerability stems from improper handling of exceptional conditions (CWE-703) in FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager products. An unauthenticated attacker can exploit this flaw by sending crafted SSL-encrypted TCP requests to repeatedly reset the fgfm conn [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2024-26006

CVE-2024-26006 is a cross-site scripting (XSS) vulnerability in FortiOS and FortiProxy's web SSL VPN UI, affecting Siemens RUGGEDCOM APE1808 devices that incorporate Fortinet NGFW technology. The vulnerability, published July 9, 2024, carries a HIGH severity CVSS 7.5 score and requires user interaction through social engineering—specifically, convincing a targeted user to bookmark a malicious Samba server [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2024-23111

A stored cross-site scripting (XSS) vulnerability exists in the reboot page of FortiOS and FortiProxy, affecting Siemens RUGGEDCOM APE1808 deployments that incorporate Fortinet NGFW components. The flaw stems from improper neutralization of input during web page generation (CWE-79). A remote attacker with super-admin privileges can execute arbitrary JavaScript code by sending crafted HTTP GET requests to [truncated]

LOW Siemens CVE published 2024-07-09

CVE-2024-21754

A use of password hash with insufficient computational effort vulnerability (CWE-916) affects FortiOS and FortiProxy versions embedded in the Siemens RUGGEDCOM APE1808 industrial platform. The vulnerability, published July 9, 2024, allows a privileged attacker with super-admin profile and CLI access to decrypt backup files due to weak password hashing. The CVSS 3.1 score of 1.8 (Low severity) reflects the [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2023-7066

CVE-2023-7066 is a high-severity out-of-bounds read vulnerability in Siemens JT2Go and Teamcenter Visualization products, published on 2024-07-09 and last modified on 2024-08-13. The vulnerability exists in the PDF parsing functionality of affected applications, where an out-of-bounds read past the end of an allocated structure can occur when processing specially crafted PDF files. This memory safety defe [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2023-52891

A vulnerability in Unified Automation's .NET-based OPC UA Server SDK (versions prior to 3.2.2), as used in multiple Siemens industrial products, can allow an attacker to cause high CPU load and memory exhaustion, potentially blocking server operations. The issue is related to CVE-2023-27321 affecting the OPC Foundation UA .NET Standard implementation. The vulnerability was published on July 9, 2024, with [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2023-52238

CVE-2023-52238 is a medium-severity information disclosure vulnerability affecting Siemens RUGGEDCOM industrial network devices. The web server on affected systems exposes MACsec (Media Access Control Security) keys in cleartext to authenticated users. An attacker with low-privileged credentials can retrieve these cryptographic keys and subsequently decrypt Ethernet frames intended for authorized recipien [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2023-52237

A HIGH severity vulnerability (CVSS 7.5) in Siemens RUGGEDCOM industrial network devices allows low-privileged users to access password hashes and salts for all system users, including administrators. Published July 9, 2024, and last modified August 12, 2025, this information disclosure flaw enables offline brute-force attacks against administrative credentials. The vulnerability affects 80 RUGGEDCOM prod [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2023-46720

A stack-based buffer overflow vulnerability exists in Fortinet FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.6 through 6.4.15, 6.2.9 through 6.2.16, and 6.0.13 through 6.0.18. This vulnerability allows an attacker with high privileges to execute unauthorized code or commands via specially crafted CLI commands. The vulnerability affects Siemens RUGGEDCOM APE1808, whic [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2023-32737

CVE-2023-32737 is a deserialization vulnerability in Siemens SIMATIC STEP 7 Safety V18 where the application fails to properly restrict the .NET BinaryFormatter when processing user-controllable input. This weakness enables type confusion attacks that can lead to arbitrary code execution within the affected engineering environment. The vulnerability stems from the same underlying issue documented in Micro [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2023-32735

CVE-2023-32735 is a medium-severity vulnerability (CVSS 6.5) affecting 27 Siemens industrial automation products across the TIA Portal ecosystem, published on 2024-07-09. The vulnerability stems from improper restrictions on the .NET BinaryFormatter during deserialization of hardware configuration profiles, enabling type confusion and arbitrary code execution within affected applications. This represents [truncated]

HIGH Siemens CVE published 2024-07-09

CVE-2022-45147

CVE-2022-45147 is a high-severity deserialization vulnerability in Siemens SIMATIC engineering software products, published by CISA on July 9, 2024. The vulnerability stems from improper restrictions on the .NET BinaryFormatter during deserialization of user-controllable input, enabling attackers to achieve type confusion and execute arbitrary code within affected applications. This represents a well-know [truncated]

MEDIUM Siemens CVE published 2024-07-09

CVE-2022-32260

CVE-2022-32260 is a medium-severity authentication bypass vulnerability in Siemens SINEMA Remote Connect Server. The affected application generates temporary user credentials for UMC (User Management Component) users, which an attacker could leverage to bypass authentication under certain conditions. The vulnerability was published on July 9, 2024, with a CVSS 3.1 score of 6.5. Siemens has released a vend [truncated]