PatchSiren

siemens CVE debriefs · Page 61

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-36004

A vulnerability in the i40e Intel Ethernet driver affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial controllers. The issue stems from improper use of the WQ_MEM_RECLAIM flag when creating a workqueue, which can lead to memory reclaim deadlocks under memory pressure conditions. This local attack vector requires low privileges and no user interaction, with successful exploitation [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35997

A race condition in the Linux kernel's HID I2C subsystem can cause a system lock-up on Siemens SIMATIC S7-1500 TM MFP devices with the GNU/Linux subsystem. The vulnerability stems from improper synchronization when the I2C_HID_READ_PENDING flag is set during HID report reads, potentially leaving the driver in a hung state. This is a local attack vector requiring low privileges with no user interaction, re [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35988

This CVE addresses a kernel-level defect in the RISC-V architecture's memory management for 64-bit No-MMU (NOMMU) configurations. The TASK_SIZE definition incorrectly limits userspace memory addressing, causing spurious access failures when physical RAM exists above 4GB. This is a local availability impact vulnerability with no confidentiality or integrity impact.

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35982

A vulnerability in the batman-adv (Better Approach To Mobile Ad-hoc Networking Advanced) kernel module could allow an authenticated local attacker to cause a denial of service condition through an infinite loop when attempting to resize the local Translation Table (TT). The vulnerability stems from improper loop control in the TT resizing logic, which can be triggered under specific memory pressure or tab [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35978

A memory leak vulnerability exists in the Linux kernel's Bluetooth subsystem, specifically within the hci_req_sync_complete() function. This flaw can lead to resource exhaustion and denial of service conditions on affected systems. The vulnerability has been identified in Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The issue stems from improper memory ma [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35966

A vulnerability in the Linux kernel's Bluetooth RFCOMM subsystem allows local attackers to cause denial of service through improper validation of setsockopt user input. The flaw exists in the RFCOMM (Radio Frequency Communication) protocol implementation used for Bluetooth serial port emulation. A local attacker with low privileges can exploit this to trigger a denial of service condition on affected syst [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35965

CVE-2024-35965 is a medium-severity vulnerability in the Linux kernel's Bluetooth L2CAP subsystem, specifically affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The flaw involves improper validation of user input length in the setsockopt system call, which could lead to denial of service conditions. The vulnerability was published on April 9, 2024, and has be [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35940

A null pointer dereference vulnerability exists in the Linux kernel's pstore/zone subsystem within the psz_kmsg_read function. The flaw occurs when the function fails to validate a pointer before dereferencing it, potentially leading to a kernel crash and denial of service. This affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability requires local a [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35936

CVE-2024-35936 is a medium-severity vulnerability in the Btrfs filesystem implementation within the Linux kernel, specifically affecting the `btrfs_relocate_sys_chunks()` function. The issue involves improper handling of chunk tree lookup errors, which can lead to a denial-of-service condition. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control [truncated]

LOW Siemens CVE published 2024-04-09

CVE-2024-35934

CVE-2024-35934 is a LOW severity vulnerability (CVSS 3.1: 2.5) in the Linux kernel's Shared Memory Communications (SMC) subsystem, specifically in the `smc_pnet_create_pnetids_list()` function. The issue involves excessive rtnl (rtnetlink) lock pressure that could lead to localized denial of service conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP in [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35933

A null pointer dereference vulnerability exists in the Linux kernel's Bluetooth Intel driver (btintel). The flaw occurs in the btintel_read_version function, which can dereference a null pointer under certain conditions, leading to a kernel crash and denial of service. The vulnerability requires local access with low privileges and no user interaction, making it exploitable by authenticated users on the a [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35930

A memory leak vulnerability exists in the Linux kernel's Emulex LightPulse Fibre Channel (lpfc) driver, specifically within the lpfc_rcv_padisc() function. This flaw can lead to resource exhaustion and denial of service conditions on affected systems. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. T [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35922

CVE-2024-35922 is a division-by-zero vulnerability in the Linux kernel's framebuffer monitor (fbmon) subsystem, specifically within the fb_videomode_from_videomode() function. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The flaw can be triggered when processing video mode parameters, leading to a [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35902

CVE-2024-35902 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's Reliable Datagram Sockets (RDS) subsystem, specifically affecting the `__rds_rdma_map` function where a null pointer dereference can occur. The parameter `cp` may be null, and calling `cp->cp_conn` without validation leads to a potential denial-of-service condition. This vulnerability was published on April 9, 2024, and aff [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35893

CVE-2024-35893 is a kernel information leak vulnerability in the Linux kernel's traffic control subsystem, specifically within the `act_skbmod` module. The flaw exists in `tcf_skbmod_dump()`, which copies four bytes of uninitialized kernel stack memory to user space due to a padding hole in `struct tc_skbmod`. This vulnerability was discovered by syzbot and has been resolved in the upstream Linux kernel b [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35886

CVE-2024-35886 is a vulnerability in the Linux kernel's IPv6 networking subsystem that could cause a denial of service through infinite recursion. The flaw exists in fib6_dump_done(), which could recursively call itself during netlink socket destruction under specific fault conditions, eventually exhausting the kernel stack and causing a crash. The vulnerability was triggered when a netlink dump operation [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35877

CVE-2024-35877 is a medium-severity vulnerability in the Linux kernel's x86 Page Attribute Table (PAT) memory management subsystem, specifically affecting Copy-on-Write (COW) mappings. The flaw, published on 2024-04-09 and last modified on 2026-05-14, stems from improper handling of VM_PAT in COW scenarios where page table entries (PTEs) can be replaced during write faults to point at anonymous folios. Th [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-35849

This CVE addresses an information leak vulnerability in the Linux kernel's Btrfs filesystem, specifically within the `btrfs_ioctl_logical_to_ino()` function. The vulnerability was resolved in the upstream Linux kernel. Siemens has identified this as affecting the GNU/Linux subsystem of their SIMATIC S7-1500 TM MFP industrial control product. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H) indica [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35845

This CVE addresses a missing NUL termination vulnerability in the Linux kernel's Intel wireless (iwlwifi) driver debug TLV handling. The iwl_fw_ini_debug_info_tlv structure is used as a string without guaranteed termination, which could lead to out-of-bounds read conditions. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem within their SIMATIC S7-1500 TM MFP industrial contro [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35823

CVE-2024-35823 is a memory corruption vulnerability in the Linux kernel's virtual terminal (vt) subsystem, specifically affecting the unicode buffer when deleting characters. The issue stems from improper use of memcpy() with overlapping buffers, which can lead to buffer corruption. This is the same class of vulnerability previously fixed for the VGA text buffer in kernel commit 39cdb68c64d8. The resoluti [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-35815

A vulnerability in the Linux kernel's asynchronous I/O (AIO) subsystem could allow a local attacker to cause a denial of service condition. The flaw exists in the fs/aio code where kiocb_set_cancel_fn() may receive a struct kiocb pointer that is not embedded within struct aio_kiocb. Due to compiler-dependent behavior, the req->ki_ctx read could occur before the IOCB_AIO_RW flag check, potentially leading [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-3388

CVE-2024-3388 is a medium-severity vulnerability affecting the GlobalProtect Gateway in Palo Alto Networks PAN-OS software. The vulnerability enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, the attacker cannot receive response packets from those internal assets, limiting the attack's effectiveness to one-way communication. This vulnerabil [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-3387

A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-3386

An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.

HIGH Siemens CVE published 2024-04-09

CVE-2024-3383

A vulnerability in Palo Alto Networks PAN-OS software's processing of data from Cloud Identity Engine (CIE) agents enables unauthorized modification of User-ID groups. This affects Siemens RUGGEDCOM APE1808 devices configured with Palo Alto Networks Virtual NGFW, potentially causing inappropriate access control decisions—users may be incorrectly denied or granted access to network resources based on exist [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-31978

A path traversal vulnerability in Siemens SINEC NMS allows authenticated attackers to download arbitrary files from the file system via a monitoring data export API endpoint. Under certain conditions, accessed files may be deleted from the system. The vulnerability was disclosed on April 9, 2024, with a vendor fix available in version 2.0 SP2 or later.

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-27419

A data race vulnerability exists in the Linux kernel's NET/ROM amateur packet radio protocol implementation. The `sysctl_net_busy_read` value can be read while being concurrently modified, potentially leading to inconsistent state. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The vulnerability is local in nature, requiring low privileges and [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-27078

CVE-2024-27078 is a memory leak vulnerability in the Linux kernel's Video4Linux2 Test Pattern Generator (v4l2-tpg) subsystem. The flaw exists in the `tpg_alloc` function where resources allocated within `for` loops are not properly deallocated in error-handling paths. Since `tpg_free` is only called when `tpg_alloc` returns 0, any error path before successful completion results in resource leaks. This vul [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-27077

CVE-2024-27077 is a HIGH severity memory leak vulnerability in the Linux kernel's Video4Linux2 (V4L2) memory-to-memory framework. The flaw exists in the `v4l2_m2m_register_entity` function where `entity->name` is allocated but not freed in error-handling paths, leading to memory exhaustion over time. This vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial c [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-27076

CVE-2024-27076 is a memory leak vulnerability in the Linux kernel's media subsystem, specifically within the i.MX CSC/scaler driver. The issue occurs when memory allocated via v4l2_ctrl_handler_init is not properly freed on release, leading to resource exhaustion over time. This vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The CVSS 3 [truncated]