These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2022-47629 is a critical integer overflow vulnerability in Libksba versions prior to 1.6.3, specifically affecting the CRL (Certificate Revocation List) signature parser. The vulnerability was published on April 9, 2024, and most recently modified on May 13, 2025. Siemens RUGGEDCOM APE1808 devices are affected through this upstream dependency. The vulnerability carries a CVSS 3.1 score of 9.8 (Critica [truncated]
A use-after-free vulnerability exists in the Linux kernel's DVB CA EN50221 driver (drivers/media/dvb-core/dvb_ca_en50221.c) through version 6.0.10. The flaw occurs when a disconnect happens after an open operation, due to the absence of a wait_event synchronization mechanism. This vulnerability affects Siemens TIM 1531 IRC industrial communication devices, which incorporate the vulnerable Linux kernel com [truncated]
A vulnerability in the x86 KVM subsystem of the Linux kernel before version 5.18.17 allows unprivileged guest users to compromise the guest kernel. The issue stems from mishandled TLB (Translation Lookaside Buffer) flush operations in specific KVM_VCPU_PREEMPTED situations. This vulnerability affects Siemens SIPLUS TIM 1531 IRC and TIM 1531 IRC industrial communication devices, which incorporate the vulne [truncated]
CVE-2023-6931 is a high-severity Linux kernel vulnerability in the Performance Events subsystem. The issue can allow a local attacker with the necessary permissions context to trigger a heap out-of-bounds increment/write in perf_read_group(), creating a path to local privilege escalation. NVD lists the issue as affecting Linux kernel versions from 4.3 up to, but not including, 6.7, and also includes Debia [truncated]
CVE-2024-9143 is a medium-severity memory-corruption issue in Siemens SIDIS Prime that can arise when low-level GF(2m) elliptic-curve APIs are fed untrusted explicit field-polynomial values. The advisory says the practical exposure is low in typical ECC deployments, but affected applications using exotic binary curve encodings could still face crashes and, in some cases, possible remote code execution. Si [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's IPv6 routing subsystem within the rt6_uncached_list_flush_dev() function. The vulnerability stems from a missing NULL check that was inadvertently removed by a previous commit, potentially allowing a local attacker to trigger a denial of service condition. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control syste [truncated]
A vulnerability in the VMCI (Virtual Machine Communication Interface) kernel module, specifically in the `dg_dispatch_as_host()` function, could allow a local attacker to trigger a memcpy run-time warning condition. The issue stems from improper memory handling during datagram dispatch operations in host mode. Successful exploitation could result in denial of service conditions on affected systems. The vu [truncated]
CVE-2024-35925 is a medium-severity vulnerability (CVSS 5.5) affecting the Linux kernel block layer, specifically in the blk_rq_stat_sum() function. The issue involves a division-by-zero condition that could lead to denial of service. This vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The vulnerability [truncated]
A vulnerability in the Linux kernel's ext4 filesystem could cause data corruption during online resize operations. The issue was resolved in the upstream Linux kernel. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system. The vulnerability has a medium severity rating with a CVSS score of 5.5, requiring local access and low [truncated]
CVE-2024-28182 is a denial-of-service vulnerability in the nghttp2 HTTP/2 library, affecting Siemens SINEC NMS. The nghttp2 library prior to version 1.61.0 accepts an unbounded number of HTTP/2 CONTINUATION frames even after a stream reset, causing excessive CPU consumption during HPACK header decompression. This vulnerability was published on August 13, 2024, and carries a CVSS 3.1 score of 5.3 (Medium s [truncated]
A vulnerability in the Linux kernel's netfilter nf_tables subsystem could allow a local attacker to cause a denial of service condition. The issue stems from improper handling of internal table flags during table updates, where unnecessary transaction processing occurs when no flag modifications are present. This flaw was resolved by restoring the logic to skip transactions when table updates do not modif [truncated]
A vulnerability in the Linux kernel's FAT filesystem implementation could allow information disclosure through uninitialized memory in file handles. When `fat_encode_fh_nostale()` encodes a file handle without a parent, it stores only 10 bytes, but the handle length must be a multiple of 4 bytes, leaving the last 2 bytes uninitialized. This uninitialized memory could be leaked to userspace. Siemens has id [truncated]
A kernel information leak vulnerability exists in the Linux kernel's `do_sys_name_to_handle()` function. The issue stems from the use of `kmalloc()` without proper initialization, which can expose uninitialized kernel memory to user space. The vulnerability has been resolved by switching to `kzalloc()` to ensure zero-initialization of allocated memory. This vulnerability affects Siemens SIMATIC S7-1500 TM [truncated]
CVE-2023-52426 is a medium-severity vulnerability in libexpat through version 2.5.0 that permits recursive XML Entity Expansion when XML_DTD is undefined at compile time. This condition can lead to denial of service through resource exhaustion. The vulnerability was published on August 13, 2024, and affects Siemens SINEC NMS. Siemens has released a vendor fix recommending update to version 3.0 or later. T [truncated]
CVE-2023-52425 is a denial-of-service vulnerability in libexpat through version 2.5.0, caused by excessive resource consumption when processing large tokens requiring multiple buffer fills and repeated full reparsings. The vulnerability was published on August 13, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens SINEC NMS is affected, with remediation available by updating to version 3.0 or later. The v [truncated]
CVE-2023-4807 is a product-specific OpenSSL-related bug affecting Siemens SIDIS Prime deployments on Windows 64 when running on newer x86_64 processors that support AVX512-IFMA. The issue can corrupt application state because the POLY1305 path does not restore non-volatile XMM registers before returning, instead zeroing them. Impact depends on how the calling application uses those registers and whether a [truncated]
CVE-2023-44318 is a medium-severity vulnerability affecting Siemens SCALANCE W700 series industrial wireless access points. The vulnerability stems from the use of a hardcoded cryptographic key to obfuscate configuration backup files that administrators can export from affected devices. Because the same key is embedded in all devices, an attacker who obtains a configuration backup—whether through administ [truncated]
CVE-2023-39615 is a medium-severity out-of-bounds read vulnerability in Xmlsoft Libxml2 v2.11.0, specifically within the xmlSAX2StartElement() function in /libxml2/SAX2.c. The vulnerability was published on August 13, 2024, with a CVSS 3.1 score of 6.5 (MEDIUM). The issue allows attackers to cause a Denial of Service (DoS) condition by supplying a crafted XML file. Notably, the upstream vendor's position [truncated]
A memory management flaw in the webserver implementation of Siemens SIMATIC and SIPLUS communication processors allows remote, unauthenticated attackers to trigger denial-of-service conditions. The vulnerability stems from improper memory release after use, enabling network-based attackers to exhaust webserver resources without requiring credentials or user interaction. Published on June 11, 2024, this HI [truncated]
CVE-2023-29469 is a libxml2 vulnerability that Siemens mapped to multiple SCALANCE W700 products in its advisory. A crafted XML document can trigger nondeterministic hash behavior when empty dictionary strings are processed, which can lead to logic failures and memory errors such as a double free. Siemens’ advisory identifies 19 affected SCALANCE models and directs customers to update to V3.0.0 or later. [truncated]
CVE-2023-28484 is an availability-impacting libxml2 flaw that Siemens maps to multiple SCALANCE W700 products in its 2025 advisory. The issue can be triggered by parsing certain invalid XSD schemas, leading to a NULL pointer dereference and segfault; Siemens recommends updating affected products to V3.0.0 or later.
CVE-2022-40303 is a high-severity availability issue tied to libxml2 parsing behavior and surfaced by Siemens in its SCALANCE W700 IEEE 802.11ax advisory published on 2025-02-11. The underlying flaw affects libxml2 versions before 2.10.3 when XML_PARSE_HUGE is enabled and a multi-gigabyte XML document is parsed; integer counters can overflow and lead to an invalid array access and a crash. Siemens maps th [truncated]
CVE-2022-37454 is a critical vulnerability in the Keccak XKCP SHA-3 reference implementation, affecting Siemens RUGGEDCOM APE1808 devices. The flaw involves an integer overflow in the sponge function interface that leads to a buffer overflow, potentially allowing attackers to execute arbitrary code or compromise cryptographic integrity. The vulnerability was published on April 9, 2024, with the advisory l [truncated]
CVE-2022-1271 is a HIGH severity (CVSS 8.8) arbitrary file write vulnerability in GNU gzip's zgrep utility. The flaw stems from insufficient validation when processing filenames containing two or more newlines, allowing an attacker to embed selected content and target filenames within crafted multi-line filenames. When zgrep processes such a filename, it can be forced to write attacker-controlled content [truncated]
A medium-severity authentication bypass vulnerability in Siemens SCALANCE W700 series industrial wireless access points allows authenticated attackers to escalate privileges by changing another user's password due to insufficient authorization checks. The vulnerability was disclosed in June 2024 and affects 19 product variants. Siemens has released firmware version 3.0.0 to address this issue.
CVE-2023-44322 affects multiple Siemens SCALANCE W700 wireless devices that can be configured to send email notifications for device events. If the device receives an invalid SMTP server response, it can enter an error state that disrupts email sending. In practice, a network-accessible attacker could use this to suppress notifications about certain events. Siemens and CISA published the advisory on 2025- [truncated]
CVE-2023-44320 affects multiple Siemens SCALANCE WAB/WAM/WUB/WUM wireless device variants. According to the advisory, the web interface does not properly validate authentication for certain modification actions, which can let an authenticated attacker influence the user interface configured by an administrator. Siemens and CISA rate the issue as medium severity (CVSS 4.3), and the supplied vector indicate [truncated]
CVE-2023-44319 is a medium-severity vulnerability affecting Siemens SCALANCE W700 series industrial wireless access points. The issue stems from a weak checksum algorithm used to protect configuration backup files that administrators can export from affected devices. Because the checksum mechanism is insufficiently robust, an attacker with administrative privileges could modify a configuration file and up [truncated]
CVE-2023-44317 is a high-severity vulnerability in Siemens SCALANCE W700 series industrial wireless access points. The issue stems from improper validation of uploaded X.509 certificates, which could allow an attacker with administrative privileges to execute arbitrary code on affected devices. The vulnerability was published on June 11, 2024, and a vendor fix was added to the advisory on January 14, 2025 [truncated]
CVE-2023-35788 is a high-severity vulnerability in the Linux kernel's flower classifier code, specifically in the `fl_set_geneve_opt` function within `net/sched/cls_flower.c`. The flaw allows an out-of-bounds write when processing TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets, potentially leading to denial of service or privilege escalation. The vulnerability affects Linux kernel versions prior to 6.3.7. Siemens [truncated]