PatchSiren

siemens CVE debriefs · Page 56

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2024-05-20

CVE-2024-35950

A race condition vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) client subsystem. The flaw involves incomplete protection of display modes using the dev->mode_config.mutex lock, potentially allowing a local attacker with low privileges to exploit the race condition for confidentiality, integrity, and availability impacts. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35915

CVE-2024-35915 is a medium-severity vulnerability (CVSS 5.5) affecting the NFC (Near Field Communication) NCI (NFC Controller Interface) subsystem in the Linux kernel. The vulnerability involves use of uninitialized values in the `nci_dev_up` and `nci_ntf_packet` functions, which could lead to denial of service conditions. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of t [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35910

A use-after-free vulnerability exists in the Linux kernel's TCP timer handling for kernel sockets. When TCP sockets are closed, the inet_csk_clear_xmit_timers() function uses del_timer() to stop timers, which allows ongoing timers to complete asynchronously. For user sockets, this is safe because timers hold references on the socket and the socket holds a reference on the network namespace. However, kerne [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35905

An integer overflow vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) verifier could allow out-of-bounds memory access. The flaw occurs when stack access size calculations overflow their signed integer representation, resulting in negative values that bypass safety checks. This specifically affects the check_stack_range_initialized() function in the BPF verifier, where a missing protection [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35899

A race condition vulnerability exists in the Linux kernel's netfilter nf_tables subsystem, specifically affecting the SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The flaw occurs when pending destroy workqueue operations race against the exit_net path during module removal, potentially causing use-after-free conditions when the destroy workqueue attempts to release elements after the associated set has alr [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35898

A race condition vulnerability exists in the Linux kernel's netfilter nf_tables subsystem, specifically within the `__nft_flowtable_type_get()` function. The issue arises from concurrent access between `nft_unregister_flowtable_type()` (called during `nf_flow_inet_module_exit()`) and `__nft_flowtable_type_get()` (called during `nf_tables_newflowtable()`). Without proper synchronization, iteration over the [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35897

A vulnerability in the Linux kernel's netfilter nf_tables subsystem could allow a local attacker to cause a denial of service condition. The issue occurs when table flag updates are not properly discarded when a basechain deletion is pending. Hook unregistration is deferred to the commit phase, as are hook updates triggered by the table dormant flag. When both operations are combined, this results in dele [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35896

This CVE addresses a vulnerability in the Linux kernel's netfilter subsystem where user input validation for expected length was insufficient. The issue was exposed by BPF (Berkeley Packet Filter) changes after commit 20f2505fb436, which modified cgroup setsockopt behavior to avoid kzalloc. The vulnerability occurs because the setsockopt() @optlen argument was not properly validated before copying data, p [truncated]

HIGH Siemens CVE published 2024-05-19

CVE-2024-35888

A vulnerability in the Linux kernel's ERSPAN (Encapsulated Remote Switched Port Analyzer) networking subsystem could allow a local attacker to cause a denial of service. The issue stems from improper handling of the erspan_base_hdr structure within socket buffer (skb) memory, potentially leading to out-of-bounds access or memory corruption when the header is not properly present in skb->head. The vulnerab [truncated]

CRITICAL Siemens CVE published 2024-05-19

CVE-2024-35884

## Summary CVE-2024-35884 is a vulnerability in the Linux kernel's UDP Generic Receive Offload (GRO) handling that can cause kernel crashes or packet corruption when UDP packets are incorrectly GRO-aggregated before entering network tunnels. The issue affects systems with `rx-udp-gro-forwarding` or `rx-gro-list` enabled, particularly when tunneled packets (e.g., GENEVE) have endpoints in different network [truncated]

HIGH Siemens CVE published 2024-05-17

CVE-2024-35813

A vulnerability in the Linux kernel's MMC (MultiMediaCard) core subsystem could allow a local attacker to cause a denial of service condition. The flaw exists in the close-ended FFU (Field Firmware Update) code path where an array access using `prev_idata = idatas[i - 1]` occurs without validating that the iterator `i` is greater than zero. This missing bounds check could result in a negative array index [truncated]

HIGH Siemens CVE published 2024-05-17

CVE-2024-35811

A use-after-free vulnerability exists in the Linux kernel's Broadcom FullMAC (brcmfmac) Wi-Fi driver, specifically within the `brcmf_cfg80211_detach` function. This flaw occurs during the teardown of the wireless configuration interface, where a memory region may be accessed after it has been freed, leading to potential system instability or denial of service. The vulnerability affects Siemens SIMATIC S7- [truncated]

HIGH Siemens CVE published 2024-05-17

CVE-2024-27431

This CVE addresses an uninitialized memory vulnerability in the Linux kernel's cpumap subsystem that affects XDP (eXpress Data Path) program execution. When an XDP program is attached to a cpumap entry, the xdp_rxq_info data structure within the xdp_buff backing the XDP program invocation was not zero-initialized. This causes XDP programs running in cpumap to return random memory contents as the xdp_md->r [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-27397

CVE-2024-27397 is a vulnerability in the Linux kernel's netfilter nf_tables subsystem affecting Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue involves a race condition where set elements could expire during unfinished control plane transactions, potentially leading to use-after-free conditions. The vulnerability was resolved by adding a timestamp field at transaction start, stored in the n [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-34773

A stack overflow vulnerability in Siemens Solid Edge, triggered by parsing maliciously crafted PAR files, allows local code execution in the context of the current process. The vulnerability was disclosed on May 14, 2024, with a CVSS 3.1 score of 7.8 (HIGH). Siemens has released a vendor fix in V224.0 Update 2.

HIGH Siemens CVE published 2024-05-14

CVE-2024-34772

CVE-2024-34772 is a high-severity vulnerability in Siemens Solid Edge, a CAD software suite used for product design and engineering. The flaw involves an out-of-bounds read past the end of an allocated structure when parsing specially crafted PAR (part) files. This memory safety issue could allow an attacker to execute arbitrary code within the context of the current process. The vulnerability was disclos [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-34771

A heap-based buffer overflow vulnerability exists in Siemens Solid Edge when parsing specially crafted PAR files. An attacker could exploit this to execute arbitrary code in the context of the current process. The vulnerability was disclosed on May 14, 2024, with a CVSS 3.1 score of 7.8 (HIGH). The attack requires local access and user interaction, as the victim must open a malicious PAR file. Siemens has [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-34086

CVE-2024-34086 is a high-severity out-of-bounds write vulnerability in Siemens JT2Go and Teamcenter Visualization products, published on 2024-05-14. The flaw occurs when parsing specially crafted CGM (Computer Graphics Metafile) files, potentially allowing attackers to execute arbitrary code within the context of the current process. The vulnerability affects JT2Go and multiple versions of Teamcenter Visu [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-34085

CVE-2024-34085 is a stack overflow vulnerability in Siemens JT2Go and Teamcenter Visualization products, published on 2024-05-14. The vulnerability exists in the XML parsing functionality of affected applications, where specially crafted XML files can trigger a stack overflow condition. This local attack vector requires user interaction to open a malicious file, but successful exploitation could result in [truncated]

LOW Siemens CVE published 2024-05-14

CVE-2024-33583

A hidden debug configuration item in Siemens SIMATIC RTLS Locating Manager could allow authenticated local attackers to gain insight into internal deployment configuration. The vulnerability was published on May 14, 2024, and modified on June 11, 2024. Siemens has released version V3.0.1.1 or later to address this issue.

HIGH Siemens CVE published 2024-05-14

CVE-2024-33577

A stack overflow vulnerability exists in Siemens Simcenter Femap, triggered when parsing specially crafted strings passed as arguments to an application binary. Successful exploitation allows code execution in the context of the current process. The vulnerability was disclosed on July 9, 2024, with a vendor fix available in V2406 or later.

MEDIUM Siemens CVE published 2024-05-14

CVE-2024-33498

A memory management vulnerability in Siemens SIMATIC RTLS Locating Manager allows unauthenticated remote attackers to cause denial of service through memory exhaustion. The flaw exists because affected applications fail to properly release memory allocated when processing specially crafted incoming network packets. An attacker can exploit this by sending malicious packets to exhaust available memory, caus [truncated]

MEDIUM Siemens CVE published 2024-05-14

CVE-2024-33497

A local privilege escalation vulnerability exists in Siemens SIMATIC RTLS Locating Manager Track Viewer Client. The affected client components do not properly protect credentials used for server authentication. An authenticated local attacker with Manager role access can extract these credentials and escalate privileges to Systemadministrator role. The vulnerability was published on May 14, 2024, with a C [truncated]

MEDIUM Siemens CVE published 2024-05-14

CVE-2024-33496

CVE-2024-33496 is a medium-severity vulnerability in Siemens SIMATIC RTLS Locating Manager affecting Report Clients. Published on 2024-05-14 and last modified on 2024-06-11, this issue involves improper credential protection that allows an authenticated local attacker to extract credentials and escalate privileges from Manager to Systemadministrator role. The vulnerability affects seven product variants o [truncated]

MEDIUM Siemens CVE published 2024-05-14

CVE-2024-33494

CVE-2024-33494 is a medium-severity authentication bypass vulnerability in Siemens SIMATIC RTLS Locating Manager affecting seven product variants. Published on May 14, 2024, and last modified on June 11, 2024, this flaw stems from improper authentication of heartbeat messages in components using the TeeRevProxy service. An unauthenticated remote attacker can exploit this weakness to impact availability of [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-33493

CVE-2024-33493 is a high-severity out-of-bounds read vulnerability in Siemens Solid Edge, published on 2024-05-14. The flaw occurs when parsing specially crafted PAR (part) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability requires local access and user interaction, with an attacker needing to convince a victim to open a malicious file. Siemens [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-33492

CVE-2024-33492 is a high-severity vulnerability in Siemens Solid Edge, published on May 14, 2024. The vulnerability involves an out-of-bounds read past the end of an allocated structure when parsing specially crafted PAR (part) files. This memory safety defect could allow an attacker to execute arbitrary code within the context of the current process. The CVSS 3.1 score of 7.8 reflects high impacts to con [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-33491

CVE-2024-33491 is a high-severity out-of-bounds read vulnerability in Siemens Solid Edge, published on May 14, 2024. The flaw occurs when parsing specially crafted PAR (part) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability stems from reading past the end of an allocated structure during PAR file parsing. With a CVSS 3.1 score of 7.8 (HIGH), th [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-33490

CVE-2024-33490 is a high-severity out-of-bounds read vulnerability in Siemens Solid Edge, published on 2024-05-14. The flaw occurs when parsing specially crafted PAR (part) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability stems from reading past the end of an allocated structure during PAR file parsing. With a CVSS 3.1 score of 7.8 (HIGH), this [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-33489

CVE-2024-33489 is a heap-based buffer overflow vulnerability in Siemens Solid Edge, a computer-aided design (CAD) application. The flaw exists in the application's parsing of specially crafted PAR (part) files. When a user opens a malicious PAR file, the vulnerability can trigger memory corruption, potentially allowing an attacker to execute arbitrary code within the context of the current process. The vu [truncated]