These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
This CVE addresses a missing RCU (Read-Copy-Update) protection vulnerability in the Open vSwitch kernel module's `ovs_vport_cmd_fill_info()` function. The flaw could allow a local attacker to trigger a use-after-free condition, potentially leading to privilege escalation, information disclosure, or system instability. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that [truncated]
A use-after-free vulnerability in the Btrfs filesystem implementation of the Linux kernel affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The flaw occurs when attempting to join an aborted transaction, potentially allowing a local attacker to execute arbitrary code with elevated privileges. The vulnerability carries a HIGH severity CVSS 3.1 score of 7.8 (AV:L/ [truncated]
CVE-2025-21744 is a NULL pointer dereference vulnerability in the brcmfmac Wi-Fi driver, specifically within the `brcmf_txfinalize()` function. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. A local attacker with low privileges can trigger a denial-of-service condition without user interaction. The CVSS 3.1 score of 5.5 (MEDIUM) refle [truncated]
A use-after-free (UAF) vulnerability exists in the Linux kernel's padata subsystem, specifically within the `padata_reorder` function. The padata subsystem provides parallel data processing capabilities, and the flaw arises from improper memory management during reordering operations. A local attacker with low privileges can exploit this vulnerability to achieve privilege escalation, potentially gaining f [truncated]
CVE-2025-21726 is a Use-After-Free (UAF) vulnerability in the Linux kernel's padata subsystem, specifically affecting the `reorder_work` function. The vulnerability was published on 2024-04-09 and last modified on 2026-05-14. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system. The vulnerability carries a CVSS 3.1 score of [truncated]
CVE-2025-21711 is a medium-severity integer overflow vulnerability in the Linux kernel's Amateur Radio X.25 PLP (Packet Layer Protocol) over Rose (Radio Amateur Telecommunications Society) networking implementation. The flaw exists in the `rose_setsockopt()` function within `net/rose`, where insufficient validation of user-supplied socket options can lead to integer overflows. This vulnerability was publi [truncated]
A vulnerability in the USB CDC-ACM driver of the Linux kernel, affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems. The flaw involves improper validation of control transfer buffer sizes, which could allow a local attacker with high privileges to cause denial of service conditions. The vulnerability was disclosed in April 2024 and affects the GNU/Linux subsystem of this industrial automation platform.
A memory leak vulnerability exists in the Linux kernel's BPF subsystem, specifically within the bpf_sk_select_reuseport() function. This flaw affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability allows a local attacker with low privileges to trigger a denial of service condition through memory exhaustion. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's vsock (virtual socket) subsystem, specifically within the vsock_has_data and vsock_has_space functions. This flaw can be triggered when these functions are called without proper validation of the underlying socket transport state, leading to a kernel crash and denial of service. The vulnerability affects the GNU/Linux subsystem embedded [truncated]
This CVE addresses a null-pointer dereference vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) sysctl implementation for RTO (Retransmission Timeout) minimum and maximum values. The issue stems from unsafe access to `current->nsproxy` when retrieving network namespace information during sysctl operations. When a task is exiting, `current->nsproxy` can be NULL, leading to a k [truncated]
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.
A blind XML External Entities (XXE) injection vulnerability in Palo Alto Networks PAN-OS software enables authenticated attackers to exfiltrate arbitrary files from firewalls to attacker-controlled servers. This vulnerability requires network access to the firewall management interface. The vulnerability affects Siemens RUGGEDCOM APE1808 devices when configured with Palo Alto Networks Virtual NGFW. The is [truncated]
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you 'Allow Authentication with User Credentials OR Client Certificate.'
CVE-2024-5916 is an information exposure vulnerability in Palo Alto Networks PAN-OS software that was disclosed on April 9, 2024, and last modified on May 13, 2025. The vulnerability enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator with access to the configuration log can read these sensitive credentials. The vul [truncated]
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.
CVE-2024-58085 is a medium-severity vulnerability (CVSS 5.5) affecting the TOMOYO Linux security module's tomoyo_write_control() function. The issue involves improper input validation that could allow a local attacker to cause denial of service conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems running the GNU/Linux subsystem [truncated]
A vulnerability in the rtlwifi Linux kernel Wi-Fi driver, specifically the removal of an unused check_buddy_priv function, affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that include a GNU/Linux subsystem. The vulnerability was published on April 9, 2024, and carries a CVSS 3.1 score of 6.4 (MEDIUM severity). The attack vector is local, requiring high privileges and high attack complexi [truncated]
CVE-2024-58071 is a medium-severity vulnerability (CVSS 5.5) affecting the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue, described as preventing the addition of a device that is already a team device at a lower level, was published on April 9, 2024, and last modified on May 14, 2026. The vulnerability has a local attack vector with low attack complexity, requiring low privileges but no us [truncated]
A memory leak and invalid access vulnerability exists in the rtlwifi Linux kernel Wi-Fi driver, affecting the probe error path. The flaw occurs when the driver fails to properly clean up allocated memory during device initialization failures, leading to resource exhaustion and potential system instability. This vulnerability is present in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industria [truncated]
CVE-2024-58051 is a medium-severity vulnerability (CVSS 3.1: 5.5) in the Linux kernel's IPMI IPMB driver, affecting the Siemens SIMATIC S7-1500 TM MFP industrial control system's GNU/Linux subsystem. The flaw involves a missing null pointer check on the return value of devm_kasprintf(), which can lead to a denial-of-service condition when memory allocation fails. Published on 2024-04-09 and last modified [truncated]
A signed integer overflow vulnerability exists in the Linux kernel printk subsystem when defining LOG_BUF_LEN_MAX. This flaw affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability is classified as MEDIUM severity with a CVSS 3.1 score of 5.5, indicating local attack vector with low attack complexity and low privileges required. The overflow conditio [truncated]
CVE-2024-58014 is a medium-severity vulnerability (CVSS 6.0) affecting the brcmsmac Wi-Fi driver in the Linux kernel, specifically within the `wlc_phy_iqcal_gainparams_nphy()` function. The issue involves a missing gain range check that could lead to out-of-bounds access or improper calibration parameters. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-150 [truncated]
A NULL pointer dereference vulnerability in the Linux kernel's Bluetooth L2CAP subsystem affects Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw occurs in l2cap_sock_alloc() when handling socket allocation failures, potentially causing denial of service through local system crashes. This vulnerability resides in the GNU/Linux subsystem of affected industrial control devices.
CVE-2024-57981 is a medium-severity availability vulnerability described as a NULL pointer dereference in xHCI command-abort handling. The advisory was published on 2025-03-11 and later updated on 2025-09-09. In the supplied CSAF advisory, Siemens maps the issue to SIMATIC S7-1500 TM MFP - BIOS and states that no fix is currently available.
CVE-2024-57948 is a medium-severity vulnerability (CVSS 6.7) in the Linux kernel's mac802154 subsystem, affecting IEEE 802.15.4 wireless personal area network implementations. The flaw involves a corrupted list condition in ieee802154_if_remove that occurs when removing an IEEE 802.15.4 network interface after unregistering the corresponding hardware device. The vulnerability was discovered through syzkal [truncated]
CVE-2024-57940 describes a denial-of-service condition in exfat_readdir() where a corrupted exFAT filesystem can trigger an infinite loop. In the reported scenario, a cluster links to itself and an unused directory entry prevents dentry from advancing, so the loop condition never terminates. The result can be that s_lock is never released and other tasks, such as exfat_sync_fs(), hang. The supplied CISA a [truncated]
A vulnerability in the Linux kernel's USB gadget subsystem (functionfs_bind) has been identified in the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue involves a WARN_ON condition that could lead to local denial of service conditions. The vulnerability requires local access with low privileges and has high attack complexity, limiting its exploitability. No patch is currently available from the vendor.
A use-after-free (UAF) vulnerability exists in the Linux kernel's block cgroup (blk-cgroup) subsystem. The flaw occurs in blkcg_unpin_online(), which walks up the blkcg hierarchy to release online pins. The function calls blkcg_parent(blkcg) after blkcg_destroy_blkgs(blkcg), which may have already freed the blkcg structure, resulting in a use-after-free condition. This vulnerability affects Siemens SIMATI [truncated]
A Linux kernel vulnerability in the IPv4 IP tunnel subsystem where `ip_tunnel_init_flow()` is called without holding the RCU read lock, triggering a suspicious RCU usage warning. The issue occurs when code paths traverse RCU-protected lists in non-reader sections. The fix replaces `l3mdev_master_upper_ifindex_by_index_rcu()` with `l3mdev_master_upper_ifindex_by_index()`, which properly acquires the RCU re [truncated]
A vulnerability in the Linux kernel's POSIX clock subsystem could allow a local attacker to cause a denial of service through unbalanced locking in the pc_clock_settime() function. The flaw occurs when get_clock_desc() successfully acquires a read lock on clk->rwsem and increments a file descriptor reference count, but subsequent error paths fail to release these resources. This results in lock imbalance [truncated]