These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2023-35981 is a critical buffer overflow vulnerability affecting Siemens SCALANCE W1750D industrial wireless access points. The vulnerability resides in multiple underlying services and can be exploited by sending specially crafted packets to the PAPI (Aruba's access point management protocol) UDP port 8211. Successful exploitation enables unauthenticated remote code execution with privileged user per [truncated]
CVE-2023-35980 is a critical buffer overflow vulnerability affecting Siemens SCALANCE W1750D wireless access points. The vulnerability resides in multiple underlying services and can be exploited by sending specially crafted packets to the PAPI (Aruba's access point management protocol) UDP port 8211. Successful exploitation allows unauthenticated remote attackers to execute arbitrary code with privileged [truncated]
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. The vulnerability was published on 2024-04-09 and last modified on 2024-12-10. The CVSS v3.1 score is 4.4 (MEDIUM severity). The affected product is Siemens RUGGEDCOM APE1808, as identified [truncated]
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
CVE-2022-31676 is a local privilege escalation vulnerability in VMware Tools (versions 12.0.0, 11.x.y, and 10.x.y). A malicious actor with local non-administrative access to the Guest OS can escalate privileges to root in the virtual machine. This vulnerability was originally published in VMware's security advisory and subsequently incorporated into CISA's ICS advisory ICSA-24-102-04 for Siemens RUGGEDCOM [truncated]
CVE-2021-43527 is a critical heap overflow vulnerability in NSS (Network Security Services) affecting versions prior to 3.73 or 3.68.1 ESR. The vulnerability occurs when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for CMS, S/MIME, PKCS #7, or PKCS #12 signature handling are likely impacted, as are those using NSS for certificate validation, TLS, X.509, OCSP, or CRL functionality [truncated]
CVE-2020-25658 is a Bleichenbacher timing attack vulnerability in python-rsa, a pure-Python RSA implementation. The flaw allows an attacker to decrypt portions of RSA-encrypted ciphertext by exploiting timing variations in the RSA decryption API. This vulnerability was originally disclosed in 2020 but was added to the CISA ICS advisory ICSA-24-102-04 on April 9, 2024, as part of a broader security update [truncated]
CVE-2017-9120 is a critical integer overflow vulnerability in PHP 7.x through 7.1.5 affecting the mysqli_real_escape_string function. The vulnerability allows remote attackers to trigger a buffer overflow and application crash, or potentially achieve unspecified other impacts, by supplying an excessively long string. This flaw was originally disclosed in 2017 but was incorporated into CISA's ICS advisory [truncated]
CVE-2017-8923 is a critical vulnerability in PHP's zend_string_extend function that allows remote attackers to cause denial of service or potentially achieve other impacts. The vulnerability stems from improper handling of string length calculations that can result in negative lengths when the string concatenation operator (.=) is used with long strings. This vulnerability affects PHP versions through 7.1 [truncated]
This CVE addresses a vulnerability in the Linux kernel's IP tunnel implementation where perpetual headroom growth could occur. The issue was resolved by preventing unbounded headroom expansion in net/ip_tunnel. The vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices. CISA publish [truncated]
This CVE addresses a Linux kernel vulnerability in the SCSI target core subsystem where `smp_processor_id()` was incorrectly called in preemptible code context. The vulnerability was resolved by avoiding this unsafe pattern. Siemens TIM 1531 IRC industrial communication devices are affected due to their embedded Linux kernel usage. The issue has a local attack vector requiring low privileges and can lead [truncated]
CVE-2024-26011 is a missing authentication vulnerability in multiple Fortinet products that allows remote attackers to execute unauthorized code or commands via specially crafted packets. The vulnerability affects FortiManager, FortiPAM, FortiProxy, FortiSwitchManager, FortiPortal, and FortiOS across numerous versions. Siemens has identified this as an upstream vulnerability affecting the RUGGEDCOM APE180 [truncated]
A memory buffer handling vulnerability in Siemens fire safety systems allows unauthenticated remote attackers to crash network services via malformed X.509 certificate parsing. The flaw resides in the network communication library used by engineering tools across Cerberus PRO UL and Desigo Fire Safety UL product lines. Exploitation requires an on-path attacker position to intercept engineering tool commun [truncated]
A buffer overread vulnerability in Siemens fire safety systems allows unauthenticated remote attackers to crash network services via insufficient HMAC validation. The attack requires an on-path position to intercept engineering tool communications, limiting impact to the tool itself rather than the underlying operating system.
A critical stack-based buffer overflow vulnerability exists in the network communication library used by Siemens Cerberus PRO UL and Desigo Fire Safety UL fire protection systems. The flaw stems from improper validation of X.509 certificate attribute lengths, which could enable unauthenticated remote code execution with root privileges. Exploitation requires an on-path attacker positioned to intercept eng [truncated]
CVE-2023-52583 is a vulnerability in the Linux kernel's Ceph filesystem driver related to improper use of the dget() function, which can lead to deadlock or dead code conditions. The vulnerability was resolved in the upstream Linux kernel. Siemens has identified this CVE as affecting certain industrial networking products including the RUGGEDCOM RST2428P and SCALANCE X-family switches that incorporate the [truncated]
CVE-2023-52474 is a HIGH severity vulnerability (CVSS 7.8) in the Linux kernel's IB/hfi1 driver affecting user SDMA request processing. The vulnerability stems from two bugs in handling multi-iovec user SDMA requests where an iovec other than the tail iovec does not run up to the page boundary. First, user_sdma_txadd() ignores struct user_sdma_iovec->iov.iov_len and may add up to PAGE_SIZE bytes from an i [truncated]
CVE-2023-46120 is a medium-severity vulnerability in the RabbitMQ Java client library affecting Siemens SINEC NMS. The vulnerability stems from improper enforcement of the `maxBodyLength` parameter when receiving Message objects, allowing attackers to send oversized messages that trigger memory exhaustion and Out-of-Memory (OOM) errors on consumer systems. This creates a denial-of-service condition throug [truncated]
A low-severity denial-of-service vulnerability in Siemens SCALANCE and RUGGEDCOM industrial routers allows authenticated attackers to crash the web interface by submitting oversized input during configuration changes. The device requires a manual restart to restore web interface functionality. The vulnerability stems from improper input length validation in the web-based management interface.
CVE-2023-38039 is a HIGH severity (CVSS 7.5) uncontrolled resource consumption vulnerability in curl's HTTP header handling. The flaw exists because curl did not impose limits on the number or size of HTTP response headers it would accept and store for the libcurl headers API. A malicious server can exploit this by streaming an endless series of headers, causing curl to exhaust heap memory and resulting i [truncated]
A use-after-free vulnerability exists in the Linux kernel's Renesas USB3 gadget driver, specifically in the `renesas_usb3_remove` function within `drivers/usb/gadget/udc/renesas_usb3.c`. This flaw affects Linux kernel versions prior to 6.3.2. The vulnerability was published on June 11, 2024, with a subsequent modification on July 9, 2024. Siemens has identified this vulnerability as affecting their TIM 15 [truncated]
CVE-2023-29409 is a medium-severity vulnerability affecting Siemens SIMATIC RTLS Locating Manager products. The issue stems from extremely large RSA keys in certificate chains, which can cause clients and servers to expend significant CPU time verifying signatures during TLS handshakes. This creates a potential denial-of-service condition through computational exhaustion. The vulnerability was published o [truncated]
A vulnerability in Dnsmasq before version 2.90 affects Siemens SCALANCE M-800 family industrial routers. The default maximum EDNS.0 UDP packet size was incorrectly set to 4096 bytes instead of the recommended 1232 bytes per DNS Flag Day 2020 specifications. This misconfiguration can lead to DNS resolution failures or availability issues when communicating with DNS servers that enforce stricter packet size [truncated]
A use-after-free vulnerability in curl/libcurl versions prior to 8.1.0 affects Siemens SIPLUS TIM 1531 IRC and TIM 1531 IRC industrial communication modules. The flaw occurs when libcurl's SSH server public key verification feature fails: memory containing the SHA-256 fingerprint is freed before an error message referencing that memory is returned, potentially leaking sensitive heap data through the error [truncated]
A denial-of-service vulnerability exists in the Linux Kernel Device Mapper-Multipathing sub-component, specifically within the `table_clear` function in `drivers/md/dm-ioctl.c`. The issue stems from a possible recursive locking scenario that can result in a deadlock. This vulnerability affects Siemens SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) and TIM 1531 IRC (6GK7543-1MX00-0XE0) devices. The CVSS v3.1 sco [truncated]
CVE-2023-2194 is an out-of-bounds write in the Linux kernel SLIMpro I2C device driver as exposed in Siemens SCALANCE W700 wireless products. According to the advisory, a userspace value, data->block[0], was not constrained to 0-255 and was used as the length for memcpy, which could write past the end of dma_buffer. Siemens and CISA describe the impact as a possible local crash and, in the worst case, code [truncated]
A use-after-free vulnerability in the Android binder driver (binder.c) affects Siemens TIM 1531 IRC industrial communication modules. The flaw enables local privilege escalation without requiring user interaction or additional execution privileges. Siemens has released firmware version 2.4.8 to address this vulnerability.
CVE-2023-2124 is an out-of-bounds memory access vulnerability in the Linux kernel's XFS file system, specifically triggered when a user restores an XFS image after a failure with a dirty log journal. The flaw was published on June 11, 2024, and last modified on July 9, 2024. Siemens has identified this vulnerability as affecting its TIM 1531 IRC industrial communication modules, including the SIPLUS TIM 1 [truncated]
CVE-2023-1670 is a HIGH-severity use-after-free described in the supplied advisory corpus as affecting Siemens SCALANCE product variants listed in the CISA/Siemens advisory chain. The source material says a local user could crash the system or potentially escalate privileges, and Siemens recommends updating affected products to V3.0.0 or later. The supplied record was published on 2025-02-11 and revised o [truncated]
A deadlock vulnerability in the Linux kernel's BPF subsystem affects Siemens TIM 1531 IRC industrial communication devices. The flaw allows a local attacker to trigger a system crash through the BPF subsystem's deadlock condition. Siemens has released firmware version 2.4.8 to address this issue.