PatchSiren

siemens CVE debriefs · Page 55

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2024-07-01

CVE-2024-6387

CVE-2024-6387 is a high-severity OpenSSH server regression that Siemens and CISA associate with selected SIMATIC S7-1500 CPU family products. The issue is a race condition in sshd signal handling that an unauthenticated remote attacker may be able to trigger by failing to authenticate within a set time period. The supplied advisory states that no fix is currently available for the affected Siemens product [truncated]

HIGH Siemens CVE published 2024-06-21

CVE-2024-38635

CVE-2024-38635 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's SoundWire Cadence driver, affecting the Siemens SIMATIC S7-1500 TM MFP industrial control system's GNU/Linux subsystem. The flaw involves an invalid PDI (Peripheral Device Interface) offset that can trigger a denial-of-service condition. Published on April 9, 2024, and last modified on May 14, 2026, this vulnerability requi [truncated]

HIGH Siemens CVE published 2024-06-19

CVE-2024-38599

A vulnerability in the JFFS2 (Journalling Flash File System 2) implementation within the Linux kernel affects the Siemens SIMATIC S7-1500 TM MFP industrial controller's GNU/Linux subsystem. The flaw stems from improper validation of extended attribute (xattr) node sizes during filesystem operations on flash storage. JFFS2 xattr nodes, unlike regular inode nodes, are not fragmented across multiple eraseblo [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2024-35292

A vulnerability in Siemens SIMATIC S7-200 SMART CPU devices allows attackers to exploit predictable IP ID sequence numbers, potentially leading to denial of service conditions. The affected devices use predictable IP ID sequence numbers, making them susceptible to attacks that rely on this predictability as their base method. This vulnerability has a CVSS 3.1 score of 8.2 (HIGH severity) and was published [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-35212

CVE-2024-35212 is a medium-severity vulnerability (CVSS 6.2) affecting Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0), published June 11, 2024. The vulnerability stems from insufficient input validation in the affected application, which could allow an attacker to gain unauthorized access to database entries. The attack vector is local (AV:L), requiring low attack complexity (AC:L) with no privileges [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-35211

CVE-2024-35211 is a MEDIUM severity vulnerability (CVSS 5.5) affecting Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0). The affected web server sets session cookies without security attributes (Secure, HttpOnly, or SameSite) after successful authentication. This weakness exposes session tokens to potential interception or manipulation, particularly in network-sniffing scenarios or cross-site request f [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-35210

A medium-severity vulnerability in Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) allows downgrade attacks due to missing HTTP Strict Transport Security (HSTS) enforcement on the affected web server. Published 2024-06-11 and last modified 2025-05-06, this issue could expose confidential information if an attacker successfully intercepts and downgrades HTTPS connections. The vulnerability requires loc [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-35209

A medium-severity vulnerability in Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) allows unauthorized file modification due to improper HTTP method restrictions. The affected web server permits PUT and DELETE methods, which could enable attackers to modify files without proper authorization. This vulnerability was published on June 11, 2024, and last modified on May 6, 2025. Siemens has released a ve [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-35208

CVE-2024-35208 is a medium-severity vulnerability (CVSS 6.3) affecting Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0), an industrial network monitoring product. The vulnerability involves cleartext password storage in the affected web server, which could allow an attacker in a privileged network position to obtain access credentials. The issue was published on June 11, 2024, and last modified on May [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2024-35207

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web interface of Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0). An attacker can trick an authenticated victim into clicking a malicious link, enabling arbitrary actions on the device on behalf of the victim user. The vulnerability was disclosed on June 11, 2024, with a CVSS 3.1 score of 7.8 (HIGH). Siemens has released a vendor fix in v [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2024-35206

A session management vulnerability in Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) allows attackers to obtain unauthorized access due to non-expiring sessions. Published June 11, 2024, this HIGH severity issue (CVSS 7.7) affects industrial network monitoring infrastructure where persistent sessions could enable lateral movement or unauthorized operational control. The vendor has released V1.2 as a remediation.

MEDIUM Siemens CVE published 2024-06-11

CVE-2024-33500

A privilege escalation vulnerability in Siemens Mendix applications allows authenticated users with role management capabilities to elevate access rights for other users. The attack requires guessing a target role's identifier, making exploitation more difficult but still achievable. The vulnerability affects Mendix 9, Mendix 10, and Mendix 10 (V10.6) applications. Siemens has released patched versions, a [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-50763

A denial-of-service vulnerability exists in Siemens SIMATIC and SIPLUS communication processors. When the web server is configured to allow PKCS12 certificate container import, processing incomplete certificate chains can trigger an infinite loop. An authenticated remote attacker can exploit this by importing a crafted PKCS12 container, causing the device to become unresponsive. The vulnerability requires [truncated]

CRITICAL Siemens CVE published 2024-06-11

CVE-2023-41910

A critical vulnerability in lldpd before version 1.0.17 allows remote attackers to trigger an out-of-bounds read on heap memory by sending a crafted CDP PDU packet containing specific CDP_TLV_ADDRESSES TLVs. The vulnerability exists in the cdp_decode function within daemon/protocols/cdp.c. This flaw affects Siemens SIMATIC and SIPLUS industrial communication processors that incorporate the vulnerable lldp [truncated]

LOW Siemens CVE published 2024-06-11

CVE-2023-38533

## Summary CVE-2023-38533 is a low-severity vulnerability in Siemens TIA Administrator affecting Windows systems. The issue stems from insecure permissions on a directory used for temporary download files during the update process, allowing any authenticated Windows user to potentially disrupt software updates. ## Technical Details The vulnerability exists because the affected component creates temporary [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-36799

CVE-2023-36799 is a denial-of-service vulnerability affecting .NET Core and Visual Studio, with impact extended to Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) as identified in CISA advisory ICSA-24-165-04 published June 11, 2024. The vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM severity) with vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating network-accessible attack vector, low attack com [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-36558

CVE-2023-36558 is a security feature bypass vulnerability in ASP.NET Core affecting Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Published on June 11, 2024, this vulnerability carries a CVSS 3.1 score of 6.2 (MEDIUM severity) with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C. The local attack vector with low attack complexity and no required privileges indicates that an attacke [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2023-35829

A use-after-free vulnerability exists in the Rockchip VDEC driver (rkvdec) within the Linux kernel before version 6.3.2. The flaw occurs in the rkvdec_remove function located at drivers/staging/media/rkvdec/rkvdec.c. This vulnerability has been identified as affecting Siemens industrial control system products, specifically the TIM 1531 IRC communication modules used in industrial automation environments. [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2023-27321

A high-severity denial-of-service vulnerability in OPC Foundation UA .NET Standard's ConditionRefresh request handling allows unauthenticated remote attackers to exhaust server resources. The flaw, originally reported as ZDI-CAN-20505, affects Siemens TIM 1531 IRC industrial communication modules. Attackers can trigger resource exhaustion by sending a high volume of ConditionRefresh requests without authe [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-26554

CVE-2023-26554 is an out-of-bounds write vulnerability in the mstolfp function within libntp/mstolfp.c in NTP 4.2.8p15. The flaw occurs when adding a null terminator character, potentially allowing an adversary to attack a client ntpq process. The vulnerability does not affect ntpd. Siemens SITOP UPS1600 devices incorporate affected NTP components and are exposed to this issue. CISA published advisory ICS [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-26553

CVE-2023-26553 is a medium-severity out-of-bounds write vulnerability in the Network Time Protocol (NTP) reference implementation, specifically affecting the mstolfp function in libntp/mstolfp.c within NTP 4.2.8p15. The vulnerability occurs when copying trailing numbers, potentially allowing an adversary to attack a client ntpq process. Notably, the ntpd daemon itself is not affected by this vulnerability [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2023-26552

CVE-2023-26552 is a medium-severity out-of-bounds write vulnerability in the mstolfp function within libntp/mstolfp.c in NTP 4.2.8p15. The flaw occurs when adding a decimal point, potentially allowing an adversary to attack a client ntpq process. Notably, the ntpd daemon itself cannot be attacked via this vulnerability. The issue affects Siemens SITOP UPS1600 industrial power supply units with Ethernet/PR [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2022-45887

A memory leak vulnerability exists in the Linux kernel's ttusb_dec driver (drivers/media/usb/ttusb-dec/ttusb_dec.c) through version 6.0.9, caused by a missing dvb_frontend_detach call. This vulnerability affects Siemens TIM 1531 IRC industrial communication devices, which incorporate the vulnerable kernel component. The flaw allows a local attacker with low privileges to trigger a denial-of-service condit [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2022-45886

A use-after-free vulnerability exists in the Linux kernel's DVB (Digital Video Broadcasting) networking subsystem, specifically in drivers/media/dvb-core/dvb_net.c. The flaw stems from a race condition between the .disconnect handler and dvb_device_open operations. An attacker with local access could potentially exploit this timing window to trigger memory corruption, leading to privilege escalation or sy [truncated]

HIGH Siemens CVE published 2024-06-11

CVE-2022-41742

A vulnerability in NGINX's ngx_http_mp4_module affects Siemens SINEC Traffic Analyzer, which incorporates vulnerable NGINX versions. The flaw allows a local attacker to crash worker processes or disclose memory via specially crafted audio/video files when the mp4 directive is enabled. This CVE was published on June 11, 2024, with the advisory last modified on May 6, 2025. The vulnerability requires local [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2022-40225

A floating point exception vulnerability in Siemens TIM 1531 IRC industrial communication modules can be triggered by casting an internal value under specific conditions, resulting in denial of service. The flaw was disclosed in CISA advisory ICSA-24-165-06 on June 11, 2024, with a CVSS 3.1 score of 6.5 (Medium severity). Affected products include SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) and TIM 1531 IRC [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2022-3643

A guest virtual machine can trigger a network interface controller (NIC) reset, abort, or crash in Linux-based network backends by sending specially crafted packets with split protocol headers. The vulnerability stems from netback forwarding packets that violate the Linux network stack's assumption that protocol headers reside entirely within the linear section of socket buffers (SKBs). This misbehavior h [truncated]

MEDIUM Siemens CVE published 2024-06-11

CVE-2022-3623

A race condition vulnerability in the Linux Kernel's BPF component, specifically in the follow_page_pte function within mm/gup.c, affects Siemens SIMATIC and SIPLUS industrial communication processors. The vulnerability allows remote attackers to exploit a race condition, potentially leading to integrity, confidentiality, and availability impacts. Siemens has released firmware updates to address this issue.

HIGH Siemens CVE published 2024-05-30

CVE-2024-36020

A race condition vulnerability in the Linux kernel i40e driver affects Siemens SIMATIC S7-1500 TM MFP industrial control systems. The flaw stems from a regression introduced by kernel commit 52424f974bc5, where two separate variables (an index 'v' and a VF pointer) were used interchangeably to track virtual functions. This desynchronization could cause the VF pointer to become stale and point to an uninte [truncated]

HIGH Siemens CVE published 2024-05-20

CVE-2024-35967

A vulnerability in the Linux kernel's Bluetooth SCO (Synchronous Connection Oriented) socket implementation allows local attackers to cause denial of service conditions. The flaw stems from insufficient validation of user-supplied input passed to the setsockopt system call for SCO sockets. A local attacker with low privileges can exploit this to trigger a denial of service condition on affected systems. T [truncated]