PatchSiren

siemens CVE debriefs · Page 65

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2023-11-14

CVE-2023-32032

CVE-2023-32032 is a .NET and Visual Studio elevation of privilege vulnerability affecting Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Published on June 11, 2024, this vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM severity) with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C. The attack requires local access with low privileges, high attack complexity, and no user interac [truncated]

MEDIUM Siemens CVE published 2023-11-14

CVE-2023-2975

CVE-2023-2975 describes a cryptographic integrity issue in the AES-SIV path used by Siemens SIDIS Prime: empty associated data entries can be ignored, so those entries are not authenticated. The advisory says non-empty associated data is not affected, and it rates the issue as low severity because the condition is expected to be uncommon and no affected applications were known at publication time.

HIGH Siemens CVE published 2023-11-14

CVE-2023-28260

CVE-2023-28260 is a .NET DLL hijacking vulnerability in Siemens ST7 ScadaConnect that enables remote code execution with a CVSS 3.1 score of 7.8 (HIGH). Published on June 11, 2024, this vulnerability affects ST7 ScadaConnect version 6NH7997-5DA10-0AA0. The issue stems from improper handling of DLL loading in the .NET framework component, allowing an attacker with local access to execute arbitrary code by [truncated]

HIGH Siemens CVE published 2023-11-14

CVE-2023-24936

CVE-2023-24936 is a high-severity elevation of privilege vulnerability affecting .NET, .NET Framework, and Visual Studio. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) is identified as an affected product in this advisory. The vulnerability requires user interaction and high attack complexity, with network attack vector [truncated]

MEDIUM Siemens CVE published 2023-11-14

CVE-2022-44792

A NULL pointer dereference vulnerability exists in the Net-SNMP library's handle_ipDefaultTTL function within agent/mibgroup/ip-mib/ip_scalars.c, affecting versions 5.8 through 5.9.3. This vulnerability has been identified in Siemens SIMATIC and SIPLUS industrial communication processors. A remote attacker with SNMP write access can trigger a denial-of-service condition by sending a crafted UDP packet, ca [truncated]

HIGH Siemens CVE published 2023-08-29

CVE-2023-4611

A use-after-free flaw was found in the Linux Kernel's memory management subsystem. This issue is caused by a race between mbind() and VMA-locked page fault. The flaw may allow a local attacker to crash the system or lead to a kernel information leak. Linux kernel maintainers, administrators, and users with untrusted local access should assess exposure and prioritize verification. The CVE record and NVD en [truncated]

HIGH Siemens CVE published 2023-06-18

CVE-2023-35823

A use-after-free vulnerability exists in the Linux kernel's SAA7134 video capture driver, specifically in the saa7134_finidev function within drivers/media/pci/saa7134/saa7134-core.c. This flaw affects Linux kernel versions prior to 6.3.2. The vulnerability was published on June 11, 2024, with a subsequent modification on July 9, 2024. Siemens has identified this vulnerability as affecting their SIPLUS TI [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2024-25062

A use-after-free vulnerability exists in libxml2 versions prior to 2.11.7 and 2.12.x prior to 2.12.5. The flaw occurs in the xmlValidatePopElement function when the XML Reader interface is used with DTD validation and XInclude expansion enabled. Processing a crafted XML document under these conditions can trigger memory corruption, potentially leading to denial of service. Siemens SINEC NMS is affected by [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2024-0232

CVE-2024-0232 is a medium-severity issue affecting Siemens SIDIS Prime. The advisory describes a heap use-after-free in SQLite's jsonParseAddNodeArray() function that can be triggered through specially crafted malicious input, with the likely outcome being a crash and denial of service. Siemens' remediation is to update SIDIS Prime to V4.0.700 or later.

HIGH Siemens CVE published 2023-06-13

CVE-2023-4921

CVE-2023-4921 describes a Linux kernel use-after-free in net/sched: sch_qfq that can be abused for local privilege escalation. In the supplied Siemens/CISA advisory corpus, the issue is tied to multiple Siemens SCALANCE wireless products, with remediation guidance to update to V3.0.0 or later. The advisory was published on 2025-02-11 and later revised on 2025-05-06 for typo fixes.

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-39193

CVE-2023-39193 is a Linux kernel Netfilter flaw that Siemens mapped to multiple SCALANCE WAB/WAM/WUB/WUM product variants in its industrial advisory. The issue can let a local privileged attacker with CAP_NET_ADMIN trigger an out-of-bounds read, which may result in a device crash or limited information disclosure. Siemens’ remediation is to update the affected products to V3.0.0 or later. The advisory was [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-39192

CVE-2023-39192 is a Linux kernel Netfilter flaw in the xt_u32 module that can let a local privileged attacker trigger an out-of-bounds read, which may result in a crash or information disclosure. In Siemens’ advisory for SCALANCE W700 IEEE 802.11ax, the issue affects 19 SCALANCE wireless products and is addressed by updating to V3.0.0 or later. CISA published the advisory on 2025-02-11 and later revised i [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-3446

CVE-2023-3446 is a denial-of-service issue tied to very slow validation of excessively long Diffie-Hellman keys or parameters. In the Siemens SIDIS Prime advisory, the risk is described as a long delay or resource exhaustion condition when untrusted DH material is checked. Siemens recommends updating SIDIS Prime to V4.0.700 or later.

HIGH Siemens CVE published 2023-06-13

CVE-2023-26495

A use-after-free vulnerability in the Open Design Alliance Drawings SDK (versions before 2024.1) affects Siemens COMOS. The flaw can be triggered when parsing specially crafted DWG files and may enable arbitrary code execution when chained with other vulnerabilities. The vulnerability was disclosed on August 13, 2024, with a CVSS 3.1 score of 7.8 (HIGH). Siemens has released COMOS V10.5 as a fix.

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-23455

CVE-2023-23455 is a Linux kernel type-confusion vulnerability in atm_tc_enqueue that can result in denial of service. Siemens’ CSAF advisory ICSA-25-044-09 maps the issue to multiple SCALANCE WAB/WAM/WUB/WUM products and directs customers to update to V3.0.0 or later.

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-23454

CVE-2023-23454 is a Linux kernel flaw in cbq_classify that can lead to a slab-out-of-bounds read and denial of service because a non-negative return can be misread as a TC_ACT_SHOT condition instead of a valid classification result. In Siemens advisory ICSA-25-044-09, the issue is mapped to 19 SCALANCE WAB/WAM/WUB/WUM product variants, and Siemens recommends updating to V3.0.0 or later.

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-1206

CVE-2023-1206 describes a denial-of-service condition tied to a hash-collision flaw in the Linux kernel IPv6 connection lookup table. According to the advisory, a new kind of SYN flood attack can push CPU usage on an IPv6-accepting server to very high levels, and the attack can be launched by a user on the local network or by a high-bandwidth connection. Siemens maps the issue to multiple SCALANCE WAB/WAM [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2023-1073

CVE-2023-1073 is a Linux kernel memory corruption issue in the HID subsystem that can be triggered when a malicious USB device is inserted. In Siemens' advisory for affected SCALANCE products, the issue is rated medium severity and can let a local or physically present attacker crash the device and potentially escalate privileges. Siemens identifies 19 affected SCALANCE models and provides a vendor fix path.

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-42329

CVE-2022-42329 is a medium-severity (CVSS 5.5) deadlock vulnerability in the Linux xen-netback driver that can be triggered by guest virtual machines. The issue occurs when packets are dropped for reasons other than XSA-392 handling while netpoll is active on the interface connected to the xen-netback driver. This vulnerability is related to CVE-2022-42328, which introduced a similar deadlock through the [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-42328

CVE-2022-42328 is a medium-severity vulnerability in the Linux netback driver that can be triggered by guest virtual machines to cause a deadlock condition. The vulnerability was introduced by the patch for XSA-392, which created a race condition when attempting to free the socket buffer (SKB) of a packet dropped due to XSA-392 handling. This results in a denial-of-service condition through system deadloc [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-39188

CVE-2022-39188 describes a Linux kernel race condition that can let a device driver free a page while stale TLB entries still exist. In the Siemens advisory published by CISA on 2025-02-11, the issue is tied to multiple SCALANCE W700 product variants and the recommended remediation is to update to V3.0.0 or later. The published CVSS score is 4.7 (MEDIUM), with impact concentrated on availability.

HIGH Siemens CVE published 2023-06-13

CVE-2022-3545

A use-after-free vulnerability in the Linux Kernel's Netronome NFP driver affects Siemens SIMATIC and SIPLUS industrial communication processors. The flaw resides in the area_cache_get function within drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c, specifically impacting IPsec functionality. With a CVSS 3.1 score of 7.8 (HIGH), this local privilege escalation vulnerability requires low attack co [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-3524

CVE-2022-3524 is a remotely reachable Linux kernel issue described as a memory leak in ipv6_renew_options within the IPv6 Handler. In the Siemens/CISA advisory, the issue affects multiple SCALANCE W-series wireless products and is remediated by updating to V3.0.0 or later.

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-3435

CVE-2022-3435 is a medium-severity out-of-bounds read vulnerability in the Linux Kernel's IPv4 Handler, specifically within the fib_nh_match function in net/ipv4/fib_semantics.c. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 4.3 (MEDIUM). The issue allows remote attackers to trigger an out-of-bounds read through manipulation of the affected function. Siemens has identified thi [truncated]

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-2663

CVE-2022-2663 describes a Linux kernel nf_conntrack_irc message-handling issue that can cause IRC traffic to be matched incorrectly. In Siemens’ advisory context, this could allow a firewall bypass when unencrypted IRC is used and nf_conntrack_irc is configured. Siemens lists multiple SCALANCE W-series products as affected and recommends updating to V3.0.0 or later.

MEDIUM Siemens CVE published 2023-06-13

CVE-2022-1015

A local privilege escalation vulnerability exists in the Linux kernel's netfilter subsystem (nf_tables_api.c). An out-of-bounds write flaw allows a local attacker to escalate privileges or cause system instability. The vulnerability requires local access with low privileges and no user interaction. Siemens has confirmed this vulnerability affects TIM 1531 IRC industrial communication modules, which incorp [truncated]

HIGH Siemens CVE published 2023-04-11

CVE-2022-44725

A local privilege escalation vulnerability exists in the OPC Foundation Local Discovery Server (LDS) component used across multiple Siemens industrial products. The LDS employs a hard-coded file path to load its configuration file. A low-privileged local attacker can place a malicious file at this predictable location, which the LDS then loads while executing with elevated privileges. This allows the atta [truncated]

MEDIUM Siemens CVE published 2023-01-10

CVE-2022-2097

CVE-2022-2097 is a cryptographic vulnerability in OpenSSL's AES OCB mode implementation on 32-bit x86 platforms using AES-NI assembly optimizations. Under specific conditions, the implementation fails to encrypt the entirety of data, potentially exposing sixteen bytes of preexisting memory content. In 'in place' encryption scenarios, this could reveal sixteen bytes of plaintext. The vulnerability does not [truncated]

Known exploited Siemens CVE published 2022-03-03

CVE-2016-8562

CVE-2016-8562 is a Siemens SIMATIC CP 1543-1 improper privilege management vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. Because CISA lists it as actively exploited, defenders should treat it as a high-priority remediation item for affected industrial control environments. The supplied corpus does not provide deeper exploit mechanics or impact details beyond the vuln [truncated]

HIGH Siemens CVE published 2021-04-19

CVE-2021-3506

An out-of-bounds memory access vulnerability in the Linux kernel's f2fs filesystem module affects 26 Siemens SCALANCE and RUGGEDCOM industrial networking products. The flaw, located in fs/f2fs/node.c in kernel versions before 5.12.0-rc4, stems from a bounds check failure that allows local attackers to access out-of-bounds memory. This can result in system crashes or information disclosure from internal ke [truncated]