PatchSiren

siemens CVE debriefs · Page 58

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Siemens CVE published 2024-05-14

CVE-2024-27939

A critical unauthenticated arbitrary file upload vulnerability in Siemens RUGGEDCOM CROSSBOW enables remote code execution with system privileges. The vulnerability was disclosed on May 14, 2024, with a CVSS 3.1 score of 9.8. Attackers can exploit this weakness without authentication to upload malicious files and achieve full system compromise. Siemens has released version 5.5 to address this vulnerabilit [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2024-0218

A Denial of Service (DoS) vulnerability exists in Nozomi Networks Guardian, affecting the RADIUS parsing functionality within the IDS module. The vulnerability stems from improper input validation in specific fields used during RADIUS packet processing. An unauthenticated attacker can exploit this flaw by sending specially crafted malformed network packets, causing the IDS module to cease updating nodes, [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2023-6916

Audit records for OpenAPI requests in Siemens RUGGEDCOM APE1808LNX devices may include sensitive information, potentially enabling unauthorized access and privilege escalation. The vulnerability carries a CVSS 3.1 score of 7.2 (HIGH severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C, indicating network attack vector, low attack complexity, high privileges required, and h [truncated]

MEDIUM Siemens CVE published 2024-05-14

CVE-2023-46280

CVE-2023-46280 is a medium-severity out-of-bounds read vulnerability in Siemens SINEC NMS that can trigger a Windows kernel Blue Screen of Death (BSOD). Published on November 12, 2024, this local attack vector requires low privileges and no user interaction, with availability impact rated high per CVSS 3.1 scoring. The vulnerability stems from improper bounds checking during memory read operations in the [truncated]

HIGH Siemens CVE published 2024-05-14

CVE-2023-33953

CVE-2023-33953 is a HIGH severity vulnerability (CVSS 7.5) affecting Siemens SIMATIC RTLS Locating Manager systems, published on 2024-05-14 and last modified on 2024-06-11. The vulnerability stems from HPACK table accounting errors in the underlying gRPC implementation that can lead to denial-of-service conditions through three attack vectors: unbounded memory buffering in the HPACK parser, unbounded CPU [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-27053

A critical vulnerability (CVSS 9.1) exists in the Linux kernel's wilc1000 Wi-Fi driver, specifically in the connection path where improper RCU (Read-Copy-Update) synchronization can lead to use-after-free conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The flaw allows network-based attack [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-27052

CVE-2024-27052 is a HIGH severity vulnerability (CVSS 3.1: 8.8) in the Linux kernel's rtl8xxxu Wi-Fi driver, affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems with GNU/Linux subsystems. The flaw involves a race condition where the c2hcmd_work workqueue may continue running after the driver is stopped, potentially leading to use-after-free or memory corruption conditions. Published on 202 [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26974

A race condition vulnerability exists in the Linux kernel's Intel QuickAssist Technology (QAT) crypto driver during Advanced Error Reporting (AER) recovery. The flaw occurs when concurrent operations access shared state during PCIe error recovery, potentially leading to memory corruption or use-after-free conditions. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the G [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26961

A use-after-free vulnerability exists in the Linux kernel's mac802154 IEEE 802.15.4 subsystem. The flaw occurs in the mac802154_llsec_key_del function where Link Layer Security (LLSEC) key resources are not properly released, leading to potential memory corruption. This vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The issue was resol [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26960

A race condition vulnerability exists in the Linux kernel's swap memory management subsystem, specifically between the `free_swap_and_cache()` and `swapoff()` functions. This flaw could allow a local attacker to trigger a denial of service condition. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The issue was resolved in the upstr [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26958

A use-after-free (UAF) vulnerability in the Linux kernel's NFS direct write path was resolved in the upstream kernel. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The flaw occurs during NFS direct write operations where improper memory management could lead to memory corruption. With a CVSS 3.1 score of 7.8 (HIGH), this local vul [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26951

CVE-2024-26951 is a vulnerability in the Linux kernel's WireGuard implementation, specifically within the netlink interface. The issue involves improper validation of peer state during netlink operations, where a dangling peer could be accessed after it has been marked for removal. The vulnerability was resolved by changing the validation logic from checking an empty list to using the `is_dead` flag, whic [truncated]

HIGH Siemens CVE published 2024-05-01

CVE-2024-26950

A vulnerability in the Linux kernel's WireGuard netlink interface could allow a local attacker to cause a denial of service condition. The issue stems from improper device access patterns in the WireGuard netlink code path, where the device was accessed through peer structures rather than through the proper context (ctx) mechanism. This flaw was resolved by modifying the code to access the device through [truncated]

HIGH Siemens CVE published 2024-04-17

CVE-2024-26898

A use-after-free vulnerability exists in the Linux kernel's ATA over Ethernet (AoE) subsystem, specifically within the aoecmd_cfg_pkts function. This flaw could allow a local attacker with low privileges to potentially achieve high confidentiality, integrity, and availability impacts. The vulnerability was resolved in the upstream Linux kernel. Siemens has identified this issue as affecting the GNU/Linux [truncated]

HIGH Siemens CVE published 2024-04-17

CVE-2024-26895

CVE-2024-26895 is a use-after-free vulnerability in the Linux kernel's wilc1000 Wi-Fi driver, affecting the cleanup of virtual interfaces (vif). The flaw occurs when all interfaces are being cleaned up, potentially leading to memory corruption. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system. The vulnerability was publi [truncated]

HIGH Siemens CVE published 2024-04-17

CVE-2024-26885

CVE-2024-26885 is a HIGH severity vulnerability (CVSS 7.8) in the Linux kernel's BPF subsystem affecting DEVMAP_HASH operations on 32-bit architectures. The flaw stems from an integer overflow condition during hash bucket allocation when rounding max_entries to the next power of two. On 32-bit systems, the rounding operation itself can trigger undefined behavior through a 32-bit left shift on unsigned lon [truncated]

HIGH Siemens CVE published 2024-04-17

CVE-2024-26883

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem affects the stackmap overflow check on 32-bit architectures. The flaw could allow a local attacker with low privileges to cause a denial of service (system crash) due to an improper overflow check. Siemens has confirmed this vulnerability affects the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control device. The [truncated]

HIGH Siemens CVE published 2024-04-17

CVE-2024-26882

CVE-2024-26882 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's IP tunnel implementation, specifically within the `ip_tunnel_rcv()` function. The flaw involves improper handling of inner packet headers during IP tunnel reception, which can lead to denial-of-service conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2026-22796

A type confusion vulnerability in OpenSSL's PKCS#7 signature verification allows denial-of-service via malformed signed data. The vulnerability exists in the PKCS7_digest_from_attributes() function, which accesses message digest attribute values without validating their ASN.1 type. When processing data where the type is not V_ASN1_OCTET_STRING, invalid memory is accessed through the ASN1_TYPE union, causi [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2026-22795

A type confusion vulnerability in PKCS#12 parsing code allows an invalid or NULL pointer dereference when processing malformed PKCS#12 files, resulting in Denial of Service. The vulnerability stems from accessing an ASN1_TYPE union member without first validating the type. The pointer manipulation is constrained to a 1-byte address space (0x00-0xFF), corresponding to the zero page which is unmapped on mos [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2025-69420

A type confusion vulnerability in OpenSSL's TimeStamp Response verification code affects the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The flaw occurs in `TS_RESP_verify_response()` where `ossl_ess_get_signing_cert()` and `ossl_ess_get_signing_cert_v2()` access signing certificate attribute values without validating the ASN.1 type. When processing a malformed TimeStamp Response with a type other [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2025-69419

CVE-2025-69419 is a high-severity (CVSS 7.4) out-of-bounds write vulnerability in OpenSSL's PKCS#12 handling, specifically affecting the `PKCS12_get_friendlyname()` function. The flaw occurs during BMPString (UTF-16BE) to UTF-8 conversion when processing maliciously crafted PKCS#12 files. The `OPENSSL_uni2utf8()` function's two-pass conversion contains a bug in the `bmp_to_utf8()` helper: it incorrectly p [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-69418

A cryptographic vulnerability in OpenSSL's low-level OCB API affects the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. When using hardware-accelerated code paths (AES-NI), inputs with lengths not divisible by 16 bytes leave trailing 1-15 bytes unencrypted and unauthenticated. The root cause is that the hardware-accelerated stream path processes full 16-byte blocks without advancing input/output poin [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-68160

CVE-2025-68160 is a heap-based out-of-bounds write vulnerability in OpenSSL's line-buffering BIO filter (BIO_f_linebuffer). The flaw occurs when large, newline-free data is written into a BIO chain where the next BIO performs short writes, potentially causing memory corruption and denial of service through application crashes. The vulnerability was published on 2024-04-09 and last modified on 2026-05-14. [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-21859

CVE-2025-21859 is a medium-severity vulnerability (CVSS 5.5) affecting the USB gadget MIDI function driver (f_midi) in the Linux kernel. The issue involves the f_midi_complete function failing to properly call queue_work, which can lead to a denial-of-service condition. This vulnerability impacts Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The vulnerability [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2025-21858

CVE-2025-21858 is a use-after-free vulnerability in the Linux kernel's Generic Network Virtualization Encapsulation (GENEVE) driver, specifically within the `geneve_find_dev()` function. The vulnerability was published on April 9, 2024, and last modified on May 14, 2026. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system p [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-21806

CVE-2025-21806 is a Siemens advisory for the SIMATIC S7-1500 TM MFP - BIOS. The issue is described as a networking-stability problem involving a NULL net_device condition, with impact limited to availability. The CVSS vector provided by the advisory indicates a local attack path with low privileges and high availability impact, but no confidentiality or integrity impact. As of the advisory’s latest revisi [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-21787

CVE-2025-21787 is a MEDIUM severity vulnerability (CVSS 5.5) affecting the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue involves improper validation of TEAM_OPTION_TYPE_STRING, which could lead to a denial-of-service condition. The vulnerability requires local access with low privileges and no user interaction, making it exploitable by authenticated users with shell access to the GNU/Linu [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2025-21776

CVE-2025-21776 is a publicly disclosed availability issue that the CISA/Siemens advisory maps to Siemens SIMATIC S7-1500 TM MFP - BIOS. The advisory says a test program can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer, and it lists no fix at publication time. Because the CVSS vector requires local access and high privileges, the main concern is targeted disruption on affect [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2025-21763

CVE-2025-21763 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's neighbour subsystem, specifically in the `__neigh_notify()` function. The issue involves missing RCU (Read-Copy-Update) protection, which can lead to use-after-free conditions. This vulnerability was published on 2024-04-09 and most recently modified on 2026-05-14. Siemens has identified this as affecting the GNU/Linux [truncated]