Direkt zum Inhalt
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + Hersteller

ICS-Advisories

Advisories speziell für industrielle Steuerungssysteme — von CISA ICS-CERT und direkt von Herstellern (Siemens ProductCERT, ABB PSIRT) — einschließlich Revisionshistorie (Erstveröffentlichung, Update A, Update B) und verknüpfter CVEs.

58

Gefunden

Advisory-Daten: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 06:10.

58 Advisories gefunden

SSA-814963

SSA-814963: Insecure Inherited Permission in Mendix (Revoked)

SiemensMendix Runtime

Siemens ProductCERTniedrig

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

22. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

Zusammenfassung der Gegenmaßnahmen

Siehe das offizielle CISA-Advisory für Gegenmaßnahmen.

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A22. September 2026

    Revoked advisory as the CVE is rejected

Offizielle Quelle: Siemens ProductCERT

SSA-823812

SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices

SiemensWTV676-HB6035 Web Interface

Siemens ProductCERTmiddel

Veröffentlicht

16. September 2026

Letzte Aktualisierung

16. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V3.94 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung16. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-019113

SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2023-53292CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21863CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40196CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23255CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23399CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31449CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31681CVE-2026-31682CVE-2026-31700CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43071CVE-2026-43085CVE-2026-43089CVE-2026-43116CVE-2026-43216CVE-2026-43284CVE-2026-43303CVE-2026-43492CVE-2026-43499CVE-2026-43501CVE-2026-45841CVE-2026-46015CVE-2026-46021CVE-2026-46033CVE-2026-46037CVE-2026-46040CVE-2026-46046CVE-2026-46086CVE-2026-46101CVE-2026-46116CVE-2026-46132CVE-2026-46172CVE-2026-46173CVE-2026-46174CVE-2026-46193CVE-2026-46300CVE-2026-46303CVE-2026-46306CVE-2026-46323CVE-2026-46333CVE-2026-52910CVE-2026-52912CVE-2026-52930CVE-2026-52933CVE-2026-52942CVE-2026-52943CVE-2026-52946CVE-2026-52970CVE-2026-52986CVE-2026-52998CVE-2026-52999CVE-2026-53001CVE-2026-53002CVE-2026-53006CVE-2026-53012CVE-2026-53050CVE-2026-53134CVE-2026-53218CVE-2026-53219CVE-2026-53223CVE-2026-53236CVE-2026-53239CVE-2026-53249CVE-2026-53268CVE-2026-53269CVE-2026-53275CVE-2026-53295CVE-2026-53352CVE-2026-53400CVE-2026-63810CVE-2026-64279CVE-2026-64317CVE-2026-64370CVE-2026-64371CVE-2026-64375CVE-2026-64411CVE-2026-64412CVE-2026-64413CVE-2026-64422CVE-2026-64423CVE-2026-64425CVE-2026-64538CVE-2026-64545CVE-2026-64552CVE-2026-64560

Betroffene Sektoren

Risk Evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A8. September 2026

    Added 79 CVEs; Added fix for CVE-2026-43284, CVE-2026-46300 and CVE-2026-31431

Offizielle Quelle: Siemens ProductCERT

SSA-142885

SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70

SiemensReyrolle 7SR5

Siemens ProductCERTkritisch

Risk Evaluation

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V2.70 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-157465

SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter

SiemensTeamcenter V2412

Siemens ProductCERTmiddel

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V2412.0013 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-216014

SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoch

Veröffentlicht

11. März 2025

Letzte Aktualisierung

8. September 2026

Betroffene Sektoren

Risk Evaluation

Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Restrict access to root/administrator permission for the operating system

Revisionshistorie (4)
  1. Erstveröffentlichung11. März 2025

    Publication Date

  2. Update A10. Juni 2025

    Added SIMATIC IPC RC-543A and RW-543B; Updated SIMATIC IPC3000 Smart V3, IPC 347G, IPC 527G

  3. Update B11. November 2025

    Added fix for SIMATIC IPC227G / IPC277G / IPC277G PRO / IPC327G / IPC377G

  4. Update C10. Februar 2026

    Added fix versions for IPC RW-543B and IPC RC-543B

Offizielle Quelle: Siemens ProductCERT

SSA-229470

SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Before V26.20

SiemensCPCI85 Central Processing/Communication

Siemens ProductCERThoch

Veröffentlicht

9. Juli 2026

Letzte Aktualisierung

8. September 2026

Betroffene Sektoren

Risk Evaluation

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/

Revisionshistorie (2)
  1. Erstveröffentlichung9. Juli 2026

    Publication Date

  2. Update A8. September 2026

    Added Acknowledgement

Offizielle Quelle: Siemens ProductCERT

SSA-254516

SSA-254516: Arbitrary File Upload in OIS Web Module

SiemensSiveillance Control Pro V3.0

Siemens ProductCERTkritisch

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V3.0.12.2173 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-282044

SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery

SiemensAutomation License Manager V6.0

Siemens ProductCERThoch

Veröffentlicht

12. August 2025

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery). Siemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Harden the application host to prevent local access by untrusted personnel

Revisionshistorie (4)
  1. Erstveröffentlichung12. August 2025

    Publication Date

  2. Update A9. September 2025

    Added Sahil Shah to acknowledgment; Added fix for SIMATIC Energy Suite V19, SIMATIC Energy Suite V20, SIMATIC MTP CREATOR V4.x, SIMATIC Control Function Library (CFL) V3.x, TIA Portal Test Suite V19, TIA Portal Test Suite V20, SIMATIC WinCC Visualization Architect V19, SIMATIC WinCC Visualization Architect V20, SIMATIC S7-PCT; Updated No fix planned for SIMATIC ProSave V17,SIMATIC WinCC flexible ES, SIMATIC Control Function Library (CFL) V1.x, SIMATIC Control Function Library (CFL) V2.x

  3. Update B14. Oktober 2025

    Added fix for MTP Creator V2.x, CFL V4.x, Simatic WinCC Unified Line Coordination and Simatic WinCC Unified Sequence

  4. Update C11. November 2025

    Added Fixes for PCS 7 Logic Matrix V9.1, PCS7 Advanced Process Faceplates V9.1, SIMATIC PCS 7 Basis Faceplates V9.1 PCS 7 Basis Library V9.1, SIMATIC Management Agent V9.1, SIMATIC Management Console V9.1, PCS 7 V9.1, PCS 7 V10.0

Offizielle Quelle: Siemens ProductCERT

SSA-327438

SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403

SiemensSCALANCE LPE9403 (6GK5998-3GS00-2AC2)

Siemens ProductCERThoch

Risk Evaluation

SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Restrict access to authorized and trusted personal only

Revisionshistorie (3)
  1. Erstveröffentlichung13. Mai 2025

    Publication Date

  2. Update A8. Juli 2025

    Added fix for CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40579, CVE-2025-40580

  3. Update B8. September 2026

    Added fix for devices with SINEMA Remote Connect Edge Client installed

Offizielle Quelle: Siemens ProductCERT

SSA-328642

SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products

SiemensSIMATIC AX Runtime Core Linux Common Debian

Siemens ProductCERThoch

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-330084

SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family

SiemensDesigo CC ClickOnce Client V6

Siemens ProductCERThoch

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

Zusammenfassung der Gegenmaßnahmen

Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-331739

SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products

SiemensSIMATIC PDM Maintenance Station V5.0

Siemens ProductCERThoch

Veröffentlicht

12. August 2025

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V3.18 P032 or later version

Revisionshistorie (3)
  1. Erstveröffentlichung12. August 2025

    Publication Date

  2. Update A9. September 2025

    Removed Simatic Information Server and Simatic Process Historian as they are not affected.

  3. Update B8. September 2026

    Added fix for SIMATIC PDM Maintenance Station V5.0

Offizielle Quelle: Siemens ProductCERT

SSA-434797

SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products

SiemensAI Lightweight Inference Server

Siemens ProductCERThoch

Veröffentlicht

9. Juni 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.

Revisionshistorie (4)
  1. Erstveröffentlichung9. Juni 2026

    Publication Date

  2. Update A14. Juli 2026

    Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT

  3. Update B11. August 2026

    Added RUGGEDCOM ROX II family and SIMATIC HMI Operator Device to Known Not Affected and removed SIMATIC Comfort/Mobile RT and updated SIMATIC Advanced HMI Panels and SIMATIC HMI Basic Panels to no fix available; Added fix for SIMATIC PDM V9.3 and added PCS neo V6.0 and Simatic Logon to affected products.

  4. Update C8. September 2026

    Updated remediation for AI Lightweight Inference Server to no fix planned.

Offizielle Quelle: Siemens ProductCERT

SSA-503852

SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management

SiemensIndustrial Edge Management Cloud

Siemens ProductCERTkritisch

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-517424

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

SiemensSIMOVE Fleetmanager V3.1

Siemens ProductCERThoch

Veröffentlicht

8. September 2026

Letzte Aktualisierung

8. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Configure appropriate user management by restricting services' access rights to project files

Revisionshistorie (1)
  1. Erstveröffentlichung8. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-887643

SSA-887643: Account Hijacking Vulnerability in Mendix SAML module

SiemensMendix SAML (Mendix 10 compatible)

Siemens ProductCERThoch

Veröffentlicht

3. September 2026

Letzte Aktualisierung

3. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V3.6.27 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung3. September 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-682041

SSA-682041: Cross Site Scripting Vulnerability in Element Maps

SiemensElement maps-ng V47

Siemens ProductCERThoch

Veröffentlicht

27. August 2026

Letzte Aktualisierung

27. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This vulnerability affects only the @siemens/maps-ng package. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Deploy a strict Content Security Policy (CSP)

Revisionshistorie (1)
  1. Erstveröffentlichung27. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

ICSA-26-230-02

Siemens Simcenter Nastran

SiemensSimcenter Femap

CISAhoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

18. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V2606 or later version

Revisionshistorie (3)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Added Simcenter Femap with fix

  3. Update B18. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory

Offizielle Quelle: CISA

ICSA-26-225-13

Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

CISAmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Betroffene Sektoren

Risk Evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory

Offizielle Quelle: CISA

ICSA-26-225-12

Siemens Solid Edge

SiemensSolid Edge SE2025

CISAhoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Betroffene Sektoren

Risk Evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V225.0 Update 15 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory

Offizielle Quelle: CISA

ICSA-26-225-11

Siemens Simcenter Femap

SiemensSimcenter Femap

CISAhoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Betroffene Sektoren

Risk Evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V2606.0001 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-584312 advisory

Offizielle Quelle: CISA

ICSA-26-225-10

Siemens Parasolid

SiemensParasolid V38.0

CISAhoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V38.0.235 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-138516 advisory

Offizielle Quelle: CISA

ICSA-26-225-09

Siemens Siveillance Video

SiemensSiveillance Video V2023 R3

CISAkritisch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V23.3 HotfixRev27 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens SSA-825228 advisory

Offizielle Quelle: CISA

ICSA-26-225-08

Siemens Desigo DXR and PXC Controllers

SiemensDesigo DXR2

CISAmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Initial CISA Republication of Siemens SSA-781903 advisory

Offizielle Quelle: CISA

SSA-069220

SSA-069220: Stack Overflow Vulnerability in Simcenter Nastran Before V2606

SiemensSimcenter Femap

Siemens ProductCERThoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

13. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V2606 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A13. August 2026

    Added Simcenter Femap with fix

Offizielle Quelle: Siemens ProductCERT

ICSA-26-225-07

Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

CISAhoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

12. August 2026

Betroffene Sektoren

Risk Evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V5.1 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A12. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory

Offizielle Quelle: CISA

ICSA-26-225-06

Siemens RUGGEDCOM APE1808

SiemensRUGGEDCOM APE1808

CISAmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

12. August 2026

Betroffene Sektoren

Risk Evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Zusammenfassung der Gegenmaßnahmen

Contact customer support to receive detailed information

Revisionshistorie (2)
  1. Erstveröffentlichung11. August 2026

    Publication Date

  2. Update A12. August 2026

    Initial CISA Republication of Siemens ProductCERT SSA-127084 advisory

Offizielle Quelle: CISA

SSA-077553

SSA-077553: Multiple Vulnerabilities in Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

Siemens ProductCERThoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Betroffene Sektoren

Risk Evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V5.1 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-104023

SSA-104023: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritisch

Risk Evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Zusammenfassung der Gegenmaßnahmen

Contact customer support to receive patch and update information

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A11. August 2026

    Added CVE-2026-0279, CVE-2026-0280, CVE-2026-0281, CVE-2026-0282, CVE-2026-0283, CVE-2026-0284, CVE-2026-0285, CVE-2026-0286, CVE-2026-0287 and CVE-2026-0288

Offizielle Quelle: Siemens ProductCERT

SSA-127084

SSA-127084: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Betroffene Sektoren

Risk Evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Zusammenfassung der Gegenmaßnahmen

Contact customer support to receive detailed information

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-138516

SSA-138516: Out of Bounds Read Vulnerability in Parasolid X_T File Parsing

SiemensParasolid V38.0

Siemens ProductCERThoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V38.0.235 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-306654

SSA-306654: Insyde BIOS Vulnerabilities in Siemens Industrial Products

SiemensRUGGEDCOM APE1808 - BIOS

Siemens ProductCERThoch

Risk Evaluation

Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code

Revisionshistorie (4)
  1. Erstveröffentlichung22. Februar 2022

    Publication Date

  2. Update A8. März 2022

    Corrected AV:L for all CVEs, added RUGGEDCOM APE1808 and SIMATIC IPC477E PRO

  3. Update B12. Juli 2022

    Added CVE-2021-43613, CVE-2021-43614 and CVE-2021-38489, add fix for SIMATIC Field PG M6, SIMATIC ITP1000 for all CVEs except CVE-2021-43613

  4. Update C9. August 2022

    Added fix for SIMATIC IPC227G, SIMATIC IPC277G, SIMATIC IPC327G, SIMATIC IPC377G, clarified affected versions for RUGGEDCOM APE1808

Offizielle Quelle: Siemens ProductCERT

SSA-392349

SSA-392349: Denial of Service Vulnerability in Industrial Devices

SiemensIE/PB LINK HA (6GK1411-5BB00)

Siemens ProductCERThoch

Veröffentlicht

12. Mai 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead

Revisionshistorie (3)
  1. Erstveröffentlichung12. Mai 2026

    Publication Date

  2. Update A14. Juli 2026

    Added fix for SCALANCE SC-600 family

  3. Update B11. August 2026

    Added fix for IE/PB LINK HA

Offizielle Quelle: Siemens ProductCERT

SSA-584312

SSA-584312: File Parsing Vulnerabilities in Simcenter Femap Before V2606 MP1

SiemensSimcenter Femap

Siemens ProductCERThoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Betroffene Sektoren

Risk Evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V2606.0001 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-621657

SSA-621657: File Parsing Vulnerabilities in Solid Edge Before Version SE2026 Update 7

SiemensSolid Edge SE2025

Siemens ProductCERThoch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Betroffene Sektoren

Risk Evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V225.0 Update 15 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-628843

SSA-628843: Out of Bound Read Vulnerability in TPM 2.0

SiemensSIMATIC CN 4100

Siemens ProductCERTmiddel

Veröffentlicht

14. April 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Currently no fix is planned

Revisionshistorie (2)
  1. Erstveröffentlichung14. April 2026

    Publication Date

  2. Update A11. August 2026

    Added no fix planned for SIMATIC ITP1000 and for SIMATIC Field PG M5. Added fix for SIMATIC Field PG M6

Offizielle Quelle: Siemens ProductCERT

SSA-686975

SSA-686975: IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoch

Veröffentlicht

14. Februar 2023

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update ("2022.3 IPU – BIOS Advisory" Intel-SA-00688). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.

Revisionshistorie (4)
  1. Erstveröffentlichung14. Februar 2023

    Publication Date

  2. Update A9. Mai 2023

    Added affected products SIMATIC IPC PX-39A and SIMATIC IPC PX-39A pro

  3. Update B11. Juli 2023

    Added fix for SIMATIC Field PG M5

  4. Update C8. August 2023

    Added fix for SIMATIC IPC BX-39A, SIMATIC IPC PX-39A, and SIMATIC IPC PX-39A pro

Offizielle Quelle: Siemens ProductCERT

SSA-751328

SSA-751328: Recoverable Hardcoded AES Master Key in Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

Siemens ProductCERTmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Betroffene Sektoren

Risk Evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-781903

SSA-781903: Denial of Service Vulnerability in Desigo DXR and PXC Controllers

SiemensDesigo DXR2

Siemens ProductCERTmiddel

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-825228

SSA-825228: Potential Remote Code Execution in Siveillance Video Management Servers

SiemensSiveillance Video V2023 R3

Siemens ProductCERTkritisch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Zusammenfassung der Gegenmaßnahmen

Update to V23.3 HotfixRev27 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-827968

SSA-827968: Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERThoch

Risk Evaluation

Nozomi Networks has published information on vulnerabilities in Nozomi Guardian/CMC. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Upgrade Nozomi Guardian to v26.2.0. Contact customer support to receive patch and update information

Revisionshistorie (4)
  1. Erstveröffentlichung13. Januar 2026

    Publication Date

  2. Update A14. April 2026

    Added CVE-2025-40894

  3. Update B12. Mai 2026

    Added CVE-2025-40897 and CVE-2025-40899

  4. Update C9. Juni 2026

    Added CVE-2025-40900, CVE-2025-40901, CVE-2025-40902, CVE--2025-40903 and CVE-2025-40904

Offizielle Quelle: Siemens ProductCERT

SSA-834709

SSA-834709: Missing Authentication Vulnerability in Node-RED on SIMATIC IoT2050 Advanced with Industrial OS

SiemensSIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2)

Siemens ProductCERTkritisch

Veröffentlicht

11. August 2026

Letzte Aktualisierung

11. August 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Harden the Node-RED installation (see Node-RED User Guide)

Revisionshistorie (1)
  1. Erstveröffentlichung11. August 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-864900

SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritisch

Risk Evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update Fortigate NGFW to V7.4.9 or later following the secure update recommendation procedure. Contact customer support to receive detailed information

Revisionshistorie (4)
  1. Erstveröffentlichung13. Mai 2025

    Publication Date

  2. Update A8. Juli 2025

    Added CVE-2025-24471, CVE-2025-22862, CVE-2024-50562 and CVE-2025-25250

  3. Update B12. August 2025

    Added CVE-2024-55599

  4. Update C9. September 2025

    Added CVE-2025-25248 and CVE-2025-53744

Offizielle Quelle: Siemens ProductCERT

ICSA-26-209-04

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

CISAkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

28. Juli 2026

Verknüpfte CVEs

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-46174CVE-2026-46300CVE-2026-46333

Betroffene Sektoren

Risk Evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A28. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-019113 advisory

Offizielle Quelle: CISA

ICSA-26-209-03

Siemens SIMATIC S7-PLCSIM Advanced

SiemensSIMATIC S7-PLCSIM Advanced

CISAhoch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

28. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A28. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-828211 advisory

Offizielle Quelle: CISA

ICSA-26-209-02

Siemens Mendix Runtime

SiemensMendix Runtime

CISAkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

28. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation.

Zusammenfassung der Gegenmaßnahmen

Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A28. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-814963 advisory

Offizielle Quelle: CISA

ICSA-26-209-01

Siemens Desigo CC

SiemensDesigo CC family V7

CISAkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

28. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Currently no fix is available

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A28. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-734552 advisory

Offizielle Quelle: CISA

ICSA-26-202-06

Siemens CADRA

SiemensCADRA

CISAkritisch

Risk Evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Update to V2511 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A21. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory

Offizielle Quelle: CISA

ICSA-26-202-05

Siemens IAM Client

SiemensCOMOS V10.4.5

CISAmiddel

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

21. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Update to V10.6.1 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A21. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory

Offizielle Quelle: CISA

ICSA-26-202-04

Siemens SIDIS Secured SmartPlug

SiemensSIDIS Secured SmartPlug

CISAkritisch

Risk Evaluation

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V7.26.0310 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A21. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory

Offizielle Quelle: CISA

ICSA-26-202-03

Siemens Opcenter X

SiemensOpcenter X

CISAkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

21. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V2604 or later version

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A21. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory

Offizielle Quelle: CISA

ICSA-26-202-02

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

SiemensRUGGEDCOM APE1808

CISAhoch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

21. Juli 2026

Betroffene Sektoren

Risk Evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Zusammenfassung der Gegenmaßnahmen

Contact customer support to receive patch and update information

Revisionshistorie (2)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

  2. Update A21. Juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory

Offizielle Quelle: CISA

SSA-082556

SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritisch

Veröffentlicht

10. Juni 2025

Letzte Aktualisierung

14. Juli 2026

Verknüpfte CVEs

CVE-2021-41617CVE-2023-4527CVE-2023-4806CVE-2023-4911CVE-2023-5363CVE-2023-6246CVE-2023-6779CVE-2023-6780CVE-2023-28531CVE-2023-38545CVE-2023-38546CVE-2023-44487CVE-2023-46218CVE-2023-46219CVE-2023-48795CVE-2023-51384CVE-2023-51385CVE-2023-52927CVE-2024-2961CVE-2024-6119CVE-2024-6387CVE-2024-12133CVE-2024-12243CVE-2024-24855CVE-2024-26596CVE-2024-28085CVE-2024-33599CVE-2024-33600CVE-2024-33601CVE-2024-33602CVE-2024-34397CVE-2024-37370CVE-2024-37371CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-47736CVE-2024-47809CVE-2024-49998CVE-2024-50246CVE-2024-50298CVE-2024-53166CVE-2024-56719CVE-2024-57924CVE-2024-57977CVE-2024-57996CVE-2024-58005CVE-2025-3198CVE-2025-4373CVE-2025-4598CVE-2025-5244CVE-2025-5245CVE-2025-6395CVE-2025-7425CVE-2025-7545CVE-2025-7546CVE-2025-8224CVE-2025-9230CVE-2025-9232CVE-2025-11082CVE-2025-11083CVE-2025-11412CVE-2025-11413CVE-2025-11414CVE-2025-11494CVE-2025-11495CVE-2025-11839CVE-2025-11840CVE-2025-21676CVE-2025-21682CVE-2025-21701CVE-2025-21702CVE-2025-21712CVE-2025-21724CVE-2025-21728CVE-2025-21745CVE-2025-21756CVE-2025-21758CVE-2025-21765CVE-2025-21766CVE-2025-21767CVE-2025-21795CVE-2025-21796CVE-2025-21848CVE-2025-21862CVE-2025-21864CVE-2025-21865CVE-2025-26465CVE-2025-31115CVE-2025-32988CVE-2025-32989CVE-2025-37945CVE-2025-37980CVE-2025-38058CVE-2025-38063CVE-2025-38067CVE-2025-38071CVE-2025-38079CVE-2025-38083CVE-2025-38100CVE-2025-38111CVE-2025-38124CVE-2025-38162CVE-2025-38167CVE-2025-38192CVE-2025-38198CVE-2025-38201CVE-2025-38212CVE-2025-38214CVE-2025-38215CVE-2025-38222CVE-2025-38231CVE-2025-38236CVE-2025-38280CVE-2025-38285CVE-2025-38312CVE-2025-38342CVE-2025-38350CVE-2025-38364CVE-2025-38393CVE-2025-38400CVE-2025-38430CVE-2025-38451CVE-2025-38457CVE-2025-38465CVE-2025-38466CVE-2025-38468CVE-2025-38470CVE-2025-38471CVE-2025-38477CVE-2025-38498CVE-2025-38499CVE-2025-38614CVE-2025-38685CVE-2025-38691CVE-2025-38701CVE-2025-38702CVE-2025-38704CVE-2025-38708CVE-2025-38721CVE-2025-38724CVE-2025-38727CVE-2025-39683CVE-2025-39689CVE-2025-39697CVE-2025-39724CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39783CVE-2025-39787CVE-2025-39795CVE-2025-39798CVE-2025-39866CVE-2025-39929CVE-2025-39931CVE-2025-39977CVE-2025-40022CVE-2025-40135CVE-2025-40219CVE-2025-40261CVE-2025-46836CVE-2025-59375CVE-2025-66382CVE-2025-68206CVE-2025-68265CVE-2025-71161CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3904CVE-2026-4046CVE-2026-4437CVE-2026-4438CVE-2026-5435CVE-2026-5450CVE-2026-5928CVE-2026-6238CVE-2026-23100CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-32776CVE-2026-32777CVE-2026-32778CVE-2026-40355CVE-2026-41080CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-45186CVE-2026-46174CVE-2026-46300

Betroffene Sektoren

Risk Evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.

Zusammenfassung der Gegenmaßnahmen

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisionshistorie (4)
  1. Erstveröffentlichung10. Juni 2025

    Publication Date

  2. Update A12. August 2025

    Added CVE-2025-6395, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990

  3. Update B13. Januar 2026

    Added CVE-2025-66382, CVE-2025-39929, CVE-2025-39931, CVE-2025-39977, CVE-2025-40022, CVE-2025-11082, CVE-2025-11083, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-11839, CVE-2025-11840, CVE-2025-9230, CVE-2025-9232, CVE-2025-3198, CVE-2025-5244, CVE-2025-5245, CVE-2025-7545, CVE-2025-7546, CVE-2025-8224, CVE-2025-7425, CVE-2025-59375

  4. Update C10. Februar 2026

    Added 22 CVEs

Offizielle Quelle: Siemens ProductCERT

SSA-096828

SSA-096828: Token Invalidation Vulnerability in Opcenter X Before V2604

SiemensOpcenter X

Siemens ProductCERTkritisch

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

14. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Zusammenfassung der Gegenmaßnahmen

Update to V2604 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-288252

SSA-288252: Unquoted Search Path Vulnerability in IAM Client

SiemensCOMOS V10.4.5

Siemens ProductCERTmiddel

Veröffentlicht

14. Juli 2026

Letzte Aktualisierung

14. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Update to V10.6.1 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-470355

SSA-470355: Zlib and Foxit Vulnerabilities in CADRA

SiemensCADRA

Siemens ProductCERTkritisch

Risk Evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Zusammenfassung der Gegenmaßnahmen

Update to V2511 or later version

Revisionshistorie (1)
  1. Erstveröffentlichung14. Juli 2026

    Publication Date

Offizielle Quelle: Siemens ProductCERT

SSA-555707

SSA-555707: Information Disclosure Vulnerability in Simcenter STAR-CCM+

SiemensSimcenter STAR-CCM+

Siemens ProductCERTmiddel

Veröffentlicht

9. August 2022

Letzte Aktualisierung

14. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system's host, user, and display name. Siemens has updated the public Power-on-Demand public license server.

Zusammenfassung der Gegenmaßnahmen

Avoid using sensitive or personal data in user, host and display names

Revisionshistorie (2)
  1. Erstveröffentlichung9. August 2022

    Publication Date

  2. Update A14. Juli 2026

    Added fix for Simcenter STAR-CCM+

Offizielle Quelle: Siemens ProductCERT