These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2024-32742 is a HIGH severity vulnerability (CVSS 7.6) affecting the Siemens SIMATIC CN 4100 industrial communication device. Published on May 14, 2024, this vulnerability stems from an unrestricted USB port on the affected device. An attacker with local physical access could exploit this port to boot an alternative operating system, thereby gaining complete read/write access to the device's filesyste [truncated]
A critical vulnerability in Siemens SIMATIC CN 4100 industrial communication devices exposes undocumented user accounts with hardcoded credentials. Published on May 14, 2024, this flaw enables unauthenticated attackers to compromise affected devices both locally and remotely. The vulnerability carries a CVSS 3.1 score of 9.8 (Critical) due to its network attack vector, low complexity, and high impact acro [truncated]
A null pointer dereference vulnerability exists in Siemens JT2Go and Teamcenter Visualization products when parsing specially crafted X_T files. An attacker can exploit this flaw to crash the affected application, resulting in a denial of service condition. The vulnerability requires local access and user interaction, with a CVSS 3.1 score of 3.3 (Low severity). The issue was disclosed on August 13, 2024, [truncated]
CVE-2024-32636 is a high-severity out-of-bounds read vulnerability in Siemens JT2Go and Teamcenter Visualization products, published on 2024-08-13. The flaw occurs when parsing specially crafted X_T (Parasolid) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability affects JT2Go and multiple versions of Teamcenter Visualization (V14.2, V14.3, and V23 [truncated]
CVE-2024-32635 is a high-severity out-of-bounds read vulnerability in Siemens JT2Go and Teamcenter Visualization products, published 2024-08-13. The flaw occurs when parsing specially crafted X_T (Parasolid) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability affects JT2Go and multiple versions of Teamcenter Visualization (V14.2, V14.3, V2312). Si [truncated]
CVE-2024-32066 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published on July 9, 2024. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21578) and affects Simcenter [truncated]
CVE-2024-32065 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published on July 9, 2024. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21577) and affects Simcenter [truncated]
CVE-2024-32064 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published 2024-07-09. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21575). Siemens has released a ve [truncated]
CVE-2024-32063 is a high-severity type confusion vulnerability in Siemens Simcenter Femap, published on 2024-07-09. The flaw exists in the application's parsing of IGS (Initial Graphics Exchange Specification) files, where improper type handling during file processing can lead to arbitrary code execution within the context of the current process. This vulnerability was reported through the Zero Day Initia [truncated]
CVE-2024-32062 is a high-severity type confusion vulnerability in Siemens Simcenter Femap, published on 2024-07-09. The flaw occurs during parsing of IGS (Initial Graphics Exchange Specification) files and can lead to arbitrary code execution in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21568) and affects Simcenter Femap versions prior to V [truncated]
CVE-2024-32061 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published on July 9, 2024. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21566) and carries a CVSS 3. [truncated]
A high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap allows code execution when parsing malicious IGS files. The flaw, reported via the Zero Day Initiative (ZDI-CAN-21565), stems from reading past the end of an allocated structure during IGS file parsing. With a CVSS 3.1 score of 7.8, this vulnerability requires local access and user interaction but grants high impact across confide [truncated]
CVE-2024-32059 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published on July 9, 2024. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute arbitrary code in the context of the current process. The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21564) and carries a CVSS 3. [truncated]
A memory corruption vulnerability exists in Siemens Simcenter Femap when parsing specially crafted IGS (Initial Graphics Exchange Specification) files. An attacker can exploit this flaw to achieve arbitrary code execution within the context of the current process. The vulnerability was reported to Siemens through the Zero Day Initiative (ZDI-CAN-21563) and was publicly disclosed on July 9, 2024. Siemens h [truncated]
A type confusion vulnerability in Siemens Simcenter Femap, triggered during parsing of IGS (Initial Graphics Exchange Specification) files, allows code execution in the context of the current process. The vulnerability was disclosed on 2024-07-09 with a CVSS 3.1 score of 7.8 (HIGH). Siemens has released a vendor fix in version V2406 or later. CISA and Siemens recommend applying the vendor update and avoid [truncated]
CVE-2024-32055 is a high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap, published 2024-07-09. The flaw occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files, allowing an attacker to execute code in the context of the current process. The vulnerability stems from reading past the end of an allocated structure during file parsing. With a CVSS 3.1 sc [truncated]
CVE-2024-31486 is a medium-severity vulnerability affecting Siemens SICAM products, specifically the OPUPI0 AMQP/MQTT module used within the CPC80 Central Processing/Communication system. The vulnerability stems from insufficient protection of MQTT client passwords stored on affected devices. An attacker with either remote shell access or physical access to the device could retrieve these credentials, res [truncated]
CVE-2024-31485 is a high-severity command injection vulnerability in the web interface of Siemens SICAM products, specifically affecting the CPC80 Central Processing/Communication module and related components. The vulnerability stems from missing server-side input sanitation, allowing an authenticated privileged remote attacker to execute arbitrary code with root privileges. Published on May 14, 2024, an [truncated]
CVE-2024-31484 is a HIGH severity vulnerability (CVSS 7.8) affecting Siemens SICAM RTU components, published on June 11, 2024. The vulnerability stems from improper null termination during parsing of a specific HTTP header, which can lead to code execution in the context of the current process or cause denial of service conditions. The affected products include CPCX26 Central Processing/Communication, ETA [truncated]
A critical vulnerability in Siemens SIMATIC RTLS Locating Manager allows man-in-the-middle attackers to eavesdrop on and modify client-side resources transmitted without proper cryptographic protection. The vulnerability requires network-level access between the RTLS Locating Manager server and clients. Siemens has released version V3.0.1.1 to address this issue.
CVE-2024-30208 is a medium-severity vulnerability in Siemens SIMATIC RTLS Locating Manager affecting seven product variants. The DBTest diagnostic tool fails to properly enforce access restrictions, allowing an authenticated local attacker to extract sensitive information from memory. Published on May 14, 2024, and last modified on June 11, 2024, this vulnerability carries a CVSS 3.1 score of 6.3. The att [truncated]
CVE-2024-30207 is a critical vulnerability in Siemens SIMATIC RTLS Locating Manager products, published on 2024-05-14 and last modified on 2024-06-11. The affected systems use symmetric cryptography with a hard-coded key to protect client-server communication, which could allow an unauthenticated remote attacker to compromise confidentiality, integrity, and subsequently availability of the system. Success [truncated]
A medium-severity vulnerability in Siemens RUGGEDCOM CROSSBOW could allow an attacker to forward log messages to a specific compromised client under certain circumstances. The issue, published on May 14, 2024, stems from improper handling of log message forwarding that could be exploited to redirect sensitive log data to an attacker-controlled endpoint. Siemens has released version 5.5 or later to address [truncated]
A path traversal vulnerability in Siemens RUGGEDCOM CROSSBOW allows authenticated attackers with high privileges to overwrite arbitrary files in the installation directory. The vulnerability exists in the file download functionality, where user-specified filenames are not properly validated against directory traversal sequences. An attacker can exploit this to overwrite critical system files, potentially [truncated]
A path traversal vulnerability in Siemens RUGGEDCOM CROSSBOW allows privileged users to upload files to the root installation directory via the bulk import feature, potentially enabling remote code execution.
CVE-2024-27944 is a HIGH severity vulnerability (CVSS 7.2) in Siemens RUGGEDCOM CROSSBOW, published on 2024-05-14. The vulnerability allows a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper with system files or achieve remote code execution. The attack vector is network-based with low attack complexity, requir [truncated]
A path traversal vulnerability in Siemens RUGGEDCOM CROSSBOW allows privileged users to upload arbitrary files to the root installation directory, enabling file tampering and potential remote code execution. The vulnerability was disclosed on May 14, 2024, with a vendor fix available in version 5.5 or later.
CVE-2024-27942 is a HIGH severity vulnerability (CVSS 7.5) in Siemens RUGGEDCOM CROSSBOW, published 2024-05-14. The vulnerability allows any unauthenticated client to disconnect any active user from the server, enabling denial of service attacks that prevent legitimate users from performing actions in the system. The attack vector is network-based with low attack complexity, requiring no privileges or use [truncated]
A SQL injection vulnerability in Siemens RUGGEDCOM CROSSBOW client systems allows authenticated attackers to compromise the entire database due to improper input sanitization. The vulnerability, published 2024-05-14, carries a CVSS 3.1 score of 8.8 (HIGH) with network attack vector, low attack complexity, and low privileges required. Siemens has released version 5.5 as a remediation. CISA published adviso [truncated]
CVE-2024-27940 is a high-severity SQL injection vulnerability in Siemens RUGGEDCOM CROSSBOW, published on May 14, 2024. The vulnerability allows any authenticated user to send arbitrary SQL commands to the SQL server, potentially enabling full database compromise. The CVSS 3.1 score of 8.8 reflects high impact across confidentiality, integrity, and availability with network accessibility and low attack co [truncated]