These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2023-44373 affects multiple Siemens SCALANCE W7xx industrial wireless devices that do not properly sanitize an input field. According to the advisory, an authenticated remote attacker with administrative privileges could inject code or spawn a system root shell. The issue is described as a follow-up to CVE-2022-36323 and is rated critical.
CVE-2022-36325 is a medium-severity DOM-based XSS affecting multiple Siemens SCALANCE wireless device models listed in the advisory. The issue is caused by improper sanitization of user-controlled data when rendering the web interface, which can let an authenticated remote attacker with administrative privileges inject code into the browser context. CISA published the advisory as ICSA-26-111-07 and republ [truncated]
CVE-2022-36324 affects multiple Siemens SCALANCE wireless devices and is rated HIGH (CVSS 7.5). According to the advisory, affected devices do not properly handle SSL/TLS parameter renegotiation, which can let an unauthenticated remote attacker bypass TCP brute-force prevention and sustain a denial-of-service condition for as long as the attack continues. Siemens lists firmware V6.6.0 or later as the fix [truncated]
CVE-2022-36323 is a critical input-sanitization issue in multiple Siemens SCALANCE wireless devices. According to the advisory corpus, an authenticated remote attacker with administrative privileges could inject code or spawn a system root shell, making compromise of the device highly consequential.
CVE-2022-31765 is a high-severity privilege-escalation issue in Siemens SCALANCE wireless devices. CISA published the advisory on 2026-04-14 and republished it on 2026-04-21 from Siemens ProductCERT SSA-019200. The supplied advisory text says the web interface’s change-password function is not properly authorized, and the supplied enrichment does not mark this CVE as a CISA KEV item.
CVE-2020-26147 is a wireless fragment-reassembly flaw tracked by CISA and Siemens for multiple SCALANCE wireless products. In affected deployments, an attacker within Wi-Fi range may be able to inject packets or exfiltrate selected fragments when fragmented frames are used with WEP, CCMP, or GCMP confidentiality.
CVE-2020-26146 is a Wi‑Fi confidentiality issue in Siemens SCALANCE wireless devices that can let an attacker within radio range recover selected fragments when fragmented frames are reassembled incorrectly. The supplied advisory material points to affected SCALANCE W7xx products running versions prior to 6.6.0, with remediation available through vendor firmware updates and temporary exposure-reduction measures.
CVE-2020-26144 affects Siemens SCALANCE wireless products covered by CISA advisory ICSA-26-111-07. The advisory describes a flaw in WEP/WPA/WPA2/WPA3 handling where plaintext A-MSDU frames may be accepted if the first 8 bytes match a valid RFC1042 LLC/SNAP header for EAPOL. That condition can let an adversary inject arbitrary network packets from within Wi-Fi range, regardless of the network configuration [truncated]
CVE-2020-26143 is described in the supplied CISA/Siemens advisory corpus as a wireless integrity issue affecting multiple Siemens SCALANCE devices. The advisory says the WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi‑Fi network, which can let an adversary inject arbitrary data frames independent of the network configuration. The corpus also states that exploi [truncated]
CVE-2020-26141 is a medium-severity wireless integrity flaw tied to TKIP frame handling. The supplied advisory text says an attacker within Wi‑Fi range can inject packets and may be able to decrypt traffic in WPA/WPA2 networks that still support TKIP. The corpus also contains a product-description mismatch, so applicability should be confirmed against the exact Siemens SCALANCE model and version before re [truncated]
CVE-2020-26140 is a wireless integrity flaw described in the supplied CISA/Siemens advisory material: protected Wi-Fi implementations accept plaintext frames, which can let an attacker within Wi-Fi range inject arbitrary data frames even when the network is configured for WEP, WPA, WPA2, or WPA3. The advisory rates the issue CVSS 6.5 (medium) and recommends updating affected devices to V6.6.0 or later. If [truncated]
CVE-2020-26139 describes an access-control flaw affecting Siemens SCALANCE wireless devices: an access point can forward EAPOL frames to other clients before the sender has successfully authenticated. In the advisory corpus, this is framed as a nearby-Wi-Fi issue that can be used for denial-of-service against connected clients and may also make other client vulnerabilities easier to exploit. The supplied [truncated]
CVE-2020-24588 describes a Wi-Fi integrity issue in the 802.11 handling of A-MSDU frames. In affected Siemens SCALANCE wireless devices, an attacker within Wi-Fi range may abuse the unauthenticated A-MSDU flag to inject arbitrary network packets. Siemens’ mitigation path is to update to V6.6.0 or later and, where possible, disable A-MSDU or reduce wireless exposure.
CVE-2026-40175 is a high-severity advisory in the supplied corpus, but the record contains a notable metadata mismatch: the product fields reference Siemens gWAP versions below 3.1.1, while the vulnerability description discusses Axios and a prototype-pollution gadget chain. Based on the source material, the key defensive takeaway is to treat this as a privileged-access, high-impact issue with potential e [truncated]
CVE-2026-27664 is a network-exploitable Siemens vulnerability in SICAM 8 products that can be triggered by specially crafted XML input. The issue is an out-of-bounds write that may crash the affected service, creating a denial-of-service condition. Siemens and CISA list fixed releases for the affected CPCI85 and SICORE components.
CVE-2026-27663 is a denial-of-service vulnerability in Siemens SICAM 8 products. In the affected remote operation mode, a high volume of requests can exhaust resources, interrupting parameterization and leaving the device or service unavailable until it is reset or rebooted. CISA published the advisory on 2026-03-26 and republished it on 2026-04-02 from Siemens ProductCERT material.
CVE-2026-25605 affects Siemens SICAM SIAPP SDK versions before 2.1.7. The issue is a file-deletion validation flaw: the application may remove a file or socket when the target path or object is not properly validated. In practice, that can let an attacker delete items the process is allowed to remove, leading to denial of service or service disruption.
CVE-2026-25573 affects Siemens SICAM SIAPP SDK versions prior to V2.1.7. According to the CISA-republished Siemens advisory, the application builds shell commands from caller-provided strings and then executes them, which can let an attacker influence the command being run. Siemens and CISA describe the result as a command injection issue with potential for full system compromise. The advisory was publish [truncated]
CVE-2026-25572 affects Siemens SICAM SIAPP SDK server component versions before 2.1.7. According to CISA’s republished Siemens ProductCERT advisory, the issue is a missing maximum-length check that can let an oversized input trigger a stack overflow, crash the process, and cause denial of service.
CVE-2026-25571 is a medium-severity issue in Siemens SICAM SIAPP SDK affecting versions before V2.1.7. According to the advisory, the client component does not enforce maximum length checks on certain variables before use, which could let an attacker supply oversized input that triggers a stack overflow, crashes the process, and may result in denial of service. Siemens lists V2.1.7 or later as the fix.
Siemens SICAM SIAPP SDK contains a stack overflow condition caused by missing checks on input values. According to the public advisory, the issue can lead to code execution or denial of service. Siemens recommends updating to V2.1.7 or later, and the advisory was republished by CISA as ICSA-26-076-04.
CVE-2026-25569 is an out-of-bounds write vulnerability in Siemens SICAM SIAPP SDK. Siemens and CISA state that affected versions are earlier than V2.1.7, and the vendor remediation is to update to V2.1.7 or later. The advisory describes possible denial of service and arbitrary code execution, with a CVSS 3.1 base score of 7.4 (HIGH).
CVE-2026-22610 is a high-severity cross-site scripting issue documented in the CISA-republished Siemens SIDIS Prime advisory corpus. The advisory ties the issue to an Angular Template Compiler sanitization weakness and states that Siemens SIDIS Prime versions prior to 4.0.800 are affected. Siemens indicates the issue is fixed in version 4.0.800 and later. From a defensive standpoint, this is primarily a w [truncated]
CVE-2025-9670 is a medium-severity issue tracked by CISA for Siemens SIDIS Prime. The supplied advisory metadata identifies affected versions as earlier than 4.0.800 and describes a remotely reachable flaw with inefficient regular expression complexity, public exploit availability, and an availability-only CVSS impact (5.3). Siemens and CISA recommend updating to V4.0.800 or later.
CVE-2025-7783 is a high-severity issue published on 2026-03-10 and republished by CISA on 2026-03-12 in the Siemens SIDIS Prime advisory (ICSA-26-071-03). The advisory states that insufficiently random values in the form-data component can allow HTTP Parameter Pollution (HPP). Siemens’ remediation is to update SIDIS Prime to V4.0.800 or later. Because the affected component is a software dependency and th [truncated]
CVE-2025-6965 is a high-severity issue mapped in CISA's Siemens SIDIS Prime advisory for versions before 4.0.800. The advisory text says SQLite versions before 3.50.2 can reach a condition where aggregate terms exceed the available columns, which may lead to memory corruption. The recommended fix is to upgrade to V4.0.800 or later.
CVE-2025-69277 is a medium-severity flaw in Siemens SIDIS Prime versions before 4.0.800. In atypical custom-cryptography or untrusted-input scenarios, an embedded libsodium validation check can sometimes accept elliptic-curve points that should not be treated as valid.
CVE-2025-66412 is published as a high-severity security advisory with a stored cross-site scripting (XSS) description and a CVSS 3.1 score of 8.0. The supplied record ties the advisory to Siemens SIDIS Prime and recommends upgrading to V4.0.800 or later. At the same time, the CVE description text references an Angular Template Compiler XSS issue, which does not cleanly match the Siemens product mapping in [truncated]
CVE-2025-66035 is a credential-leak issue in Angular HttpClient’s XSRF handling. When a request uses a protocol-relative URL beginning with //, Angular can misclassify it as same-origin and automatically attach the X-XSRF-TOKEN header, potentially exposing the token to an attacker-controlled domain. The advisory states the issue is fixed in Angular 19.2.16, 20.3.14, and 21.0.1, and recommends avoiding pro [truncated]
CVE-2025-66031 is a high-severity denial-of-service issue affecting Siemens SIDIS Prime versions earlier than 4.0.800. According to the advisory, an uncontrolled recursion condition in node-forge/ASN.1 parsing can be triggered by remote, unauthenticated attackers using deep DER structures, leading to stack exhaustion and service disruption.