Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + leveranciers

ICS Advisories

Advisories specifiek gericht op industriële besturingssystemen — van CISA ICS-CERT en rechtstreeks van leveranciers (Siemens ProductCERT, ABB PSIRT) — inclusief revisiegeschiedenis (initiële publicatie, Update A, Update B) en gekoppelde CVE's.

58

Gevonden

Advisorydata: live koppeling— laatst opgehaald: 24 september 2026 om 05:14.

Filters

1 actief
Reset filters

58 advisories gevonden

SSA-814963

SSA-814963: Insecure Inherited Permission in Mendix (Revoked)

SiemensMendix Runtime

Siemens ProductCERTlaag

Gepubliceerd

14 juli 2026

Laatste update

22 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

Mitigatiesamenvatting

Zie de officiële CISA-advisory voor mitigerende maatregelen.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A22 september 2026

    Revoked advisory as the CVE is rejected

Officiële bron: Siemens ProductCERT

SSA-823812

SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices

SiemensWTV676-HB6035 Web Interface

Siemens ProductCERTmiddel

Gepubliceerd

16 september 2026

Laatste update

16 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.94 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie16 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-019113

SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritiek

Gepubliceerd

14 juli 2026

Laatste update

8 september 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2023-53292CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21863CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40196CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23255CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23399CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31449CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31681CVE-2026-31682CVE-2026-31700CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43071CVE-2026-43085CVE-2026-43089CVE-2026-43116CVE-2026-43216CVE-2026-43284CVE-2026-43303CVE-2026-43492CVE-2026-43499CVE-2026-43501CVE-2026-45841CVE-2026-46015CVE-2026-46021CVE-2026-46033CVE-2026-46037CVE-2026-46040CVE-2026-46046CVE-2026-46086CVE-2026-46101CVE-2026-46116CVE-2026-46132CVE-2026-46172CVE-2026-46173CVE-2026-46174CVE-2026-46193CVE-2026-46300CVE-2026-46303CVE-2026-46306CVE-2026-46323CVE-2026-46333CVE-2026-52910CVE-2026-52912CVE-2026-52930CVE-2026-52933CVE-2026-52942CVE-2026-52943CVE-2026-52946CVE-2026-52970CVE-2026-52986CVE-2026-52998CVE-2026-52999CVE-2026-53001CVE-2026-53002CVE-2026-53006CVE-2026-53012CVE-2026-53050CVE-2026-53134CVE-2026-53218CVE-2026-53219CVE-2026-53223CVE-2026-53236CVE-2026-53239CVE-2026-53249CVE-2026-53268CVE-2026-53269CVE-2026-53275CVE-2026-53295CVE-2026-53352CVE-2026-53400CVE-2026-63810CVE-2026-64279CVE-2026-64317CVE-2026-64370CVE-2026-64371CVE-2026-64375CVE-2026-64411CVE-2026-64412CVE-2026-64413CVE-2026-64422CVE-2026-64423CVE-2026-64425CVE-2026-64538CVE-2026-64545CVE-2026-64552CVE-2026-64560

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A8 september 2026

    Added 79 CVEs; Added fix for CVE-2026-43284, CVE-2026-46300 and CVE-2026-31431

Officiële bron: Siemens ProductCERT

SSA-142885

SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70

SiemensReyrolle 7SR5

Siemens ProductCERTkritiek

Risk evaluation

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2.70 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-157465

SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter

SiemensTeamcenter V2412

Siemens ProductCERTmiddel

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2412.0013 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-216014

SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoog

Gepubliceerd

11 maart 2025

Laatste update

8 september 2026

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Restrict access to root/administrator permission for the operating system

Revisiegeschiedenis (4)
  1. Initiële publicatie11 maart 2025

    Publication Date

  2. Update A10 juni 2025

    Added SIMATIC IPC RC-543A and RW-543B; Updated SIMATIC IPC3000 Smart V3, IPC 347G, IPC 527G

  3. Update B11 november 2025

    Added fix for SIMATIC IPC227G / IPC277G / IPC277G PRO / IPC327G / IPC377G

  4. Update C10 februari 2026

    Added fix versions for IPC RW-543B and IPC RC-543B

Officiële bron: Siemens ProductCERT

SSA-229470

SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Before V26.20

SiemensCPCI85 Central Processing/Communication

Siemens ProductCERThoog

Gepubliceerd

9 juli 2026

Laatste update

8 september 2026

Getroffen sectoren

Risk evaluation

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/

Revisiegeschiedenis (2)
  1. Initiële publicatie9 juli 2026

    Publication Date

  2. Update A8 september 2026

    Added Acknowledgement

Officiële bron: Siemens ProductCERT

SSA-254516

SSA-254516: Arbitrary File Upload in OIS Web Module

SiemensSiveillance Control Pro V3.0

Siemens ProductCERTkritiek

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.0.12.2173 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-282044

SSA-282044: DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery

SiemensAutomation License Manager V6.0

Siemens ProductCERThoog

Gepubliceerd

12 augustus 2025

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The installers used to install several Siemens products are affected by a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected installer component. This vulnerability poses a risk only during setup and installation phase of the affected applications downloaded e.g. via OSD (Online Software Delivery). Siemens has released new versions for several affected products and recommends using the latest versions during setup and installation. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Harden the application host to prevent local access by untrusted personnel

Revisiegeschiedenis (4)
  1. Initiële publicatie12 augustus 2025

    Publication Date

  2. Update A9 september 2025

    Added Sahil Shah to acknowledgment; Added fix for SIMATIC Energy Suite V19, SIMATIC Energy Suite V20, SIMATIC MTP CREATOR V4.x, SIMATIC Control Function Library (CFL) V3.x, TIA Portal Test Suite V19, TIA Portal Test Suite V20, SIMATIC WinCC Visualization Architect V19, SIMATIC WinCC Visualization Architect V20, SIMATIC S7-PCT; Updated No fix planned for SIMATIC ProSave V17,SIMATIC WinCC flexible ES, SIMATIC Control Function Library (CFL) V1.x, SIMATIC Control Function Library (CFL) V2.x

  3. Update B14 oktober 2025

    Added fix for MTP Creator V2.x, CFL V4.x, Simatic WinCC Unified Line Coordination and Simatic WinCC Unified Sequence

  4. Update C11 november 2025

    Added Fixes for PCS 7 Logic Matrix V9.1, PCS7 Advanced Process Faceplates V9.1, SIMATIC PCS 7 Basis Faceplates V9.1 PCS 7 Basis Library V9.1, SIMATIC Management Agent V9.1, SIMATIC Management Console V9.1, PCS 7 V9.1, PCS 7 V10.0

Officiële bron: Siemens ProductCERT

SSA-327438

SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403

SiemensSCALANCE LPE9403 (6GK5998-3GS00-2AC2)

Siemens ProductCERThoog

Risk evaluation

SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Restrict access to authorized and trusted personal only

Revisiegeschiedenis (3)
  1. Initiële publicatie13 mei 2025

    Publication Date

  2. Update A8 juli 2025

    Added fix for CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40579, CVE-2025-40580

  3. Update B8 september 2026

    Added fix for devices with SINEMA Remote Connect Edge Client installed

Officiële bron: Siemens ProductCERT

SSA-328642

SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products

SiemensSIMATIC AX Runtime Core Linux Common Debian

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-330084

SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family

SiemensDesigo CC ClickOnce Client V6

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

Mitigatiesamenvatting

Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-331739

SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products

SiemensSIMATIC PDM Maintenance Station V5.0

Siemens ProductCERThoog

Gepubliceerd

12 augustus 2025

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V3.18 P032 or later version

Revisiegeschiedenis (3)
  1. Initiële publicatie12 augustus 2025

    Publication Date

  2. Update A9 september 2025

    Removed Simatic Information Server and Simatic Process Historian as they are not affected.

  3. Update B8 september 2026

    Added fix for SIMATIC PDM Maintenance Station V5.0

Officiële bron: Siemens ProductCERT

SSA-434797

SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products

SiemensAI Lightweight Inference Server

Siemens ProductCERThoog

Gepubliceerd

9 juni 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.

Revisiegeschiedenis (4)
  1. Initiële publicatie9 juni 2026

    Publication Date

  2. Update A14 juli 2026

    Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT

  3. Update B11 augustus 2026

    Added RUGGEDCOM ROX II family and SIMATIC HMI Operator Device to Known Not Affected and removed SIMATIC Comfort/Mobile RT and updated SIMATIC Advanced HMI Panels and SIMATIC HMI Basic Panels to no fix available; Added fix for SIMATIC PDM V9.3 and added PCS neo V6.0 and Simatic Logon to affected products.

  4. Update C8 september 2026

    Updated remediation for AI Lightweight Inference Server to no fix planned.

Officiële bron: Siemens ProductCERT

SSA-503852

SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management

SiemensIndustrial Edge Management Cloud

Siemens ProductCERTkritiek

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Block direct internet access to IEM Pro / IEM Virtual The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-517424

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

SiemensSIMOVE Fleetmanager V3.1

Siemens ProductCERThoog

Gepubliceerd

8 september 2026

Laatste update

8 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Configure appropriate user management by restricting services' access rights to project files

Revisiegeschiedenis (1)
  1. Initiële publicatie8 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-887643

SSA-887643: Account Hijacking Vulnerability in Mendix SAML module

SiemensMendix SAML (Mendix 10 compatible)

Siemens ProductCERThoog

Gepubliceerd

3 september 2026

Laatste update

3 september 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V3.6.27 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie3 september 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-682041

SSA-682041: Cross Site Scripting Vulnerability in Element Maps

SiemensElement maps-ng V47

Siemens ProductCERThoog

Gepubliceerd

27 augustus 2026

Laatste update

27 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This vulnerability affects only the @siemens/maps-ng package. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Deploy a strict Content Security Policy (CSP)

Revisiegeschiedenis (1)
  1. Initiële publicatie27 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

ICSA-26-230-02

Siemens Simcenter Nastran

SiemensSimcenter Femap

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

18 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2606 or later version

Revisiegeschiedenis (3)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Added Simcenter Femap with fix

  3. Update B18 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-069220 advisory

Officiële bron: CISA

ICSA-26-225-13

Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-751328 advisory

Officiële bron: CISA

ICSA-26-225-12

Siemens Solid Edge

SiemensSolid Edge SE2025

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V225.0 Update 15 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-621657 advisory

Officiële bron: CISA

ICSA-26-225-11

Siemens Simcenter Femap

SiemensSimcenter Femap

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Getroffen sectoren

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2606.0001 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-584312 advisory

Officiële bron: CISA

ICSA-26-225-10

Siemens Parasolid

SiemensParasolid V38.0

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V38.0.235 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-138516 advisory

Officiële bron: CISA

ICSA-26-225-09

Siemens Siveillance Video

SiemensSiveillance Video V2023 R3

CISAkritiek

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V23.3 HotfixRev27 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens SSA-825228 advisory

Officiële bron: CISA

ICSA-26-225-08

Siemens Desigo DXR and PXC Controllers

SiemensDesigo DXR2

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Initial CISA Republication of Siemens SSA-781903 advisory

Officiële bron: CISA

SSA-069220

SSA-069220: Stack Overflow Vulnerability in Simcenter Nastran Before V2606

SiemensSimcenter Femap

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

13 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V2606 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A13 augustus 2026

    Added Simcenter Femap with fix

Officiële bron: Siemens ProductCERT

ICSA-26-225-07

Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

CISAhoog

Gepubliceerd

11 augustus 2026

Laatste update

12 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V5.1 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A12 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-077553 advisory

Officiële bron: CISA

ICSA-26-225-06

Siemens RUGGEDCOM APE1808

SiemensRUGGEDCOM APE1808

CISAmiddel

Gepubliceerd

11 augustus 2026

Laatste update

12 augustus 2026

Getroffen sectoren

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigatiesamenvatting

Contact customer support to receive detailed information

Revisiegeschiedenis (2)
  1. Initiële publicatie11 augustus 2026

    Publication Date

  2. Update A12 augustus 2026

    Initial CISA Republication of Siemens ProductCERT SSA-127084 advisory

Officiële bron: CISA

SSA-077553

SSA-077553: Multiple Vulnerabilities in Siemens License Server (SLS)

SiemensSiemens License Server (SLS)

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V5.1 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-104023

SSA-104023: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritiek

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigatiesamenvatting

Contact customer support to receive patch and update information

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A11 augustus 2026

    Added CVE-2026-0279, CVE-2026-0280, CVE-2026-0281, CVE-2026-0282, CVE-2026-0283, CVE-2026-0284, CVE-2026-0285, CVE-2026-0286, CVE-2026-0287 and CVE-2026-0288

Officiële bron: Siemens ProductCERT

SSA-127084

SSA-127084: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.

Mitigatiesamenvatting

Contact customer support to receive detailed information

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-138516

SSA-138516: Out of Bounds Read Vulnerability in Parasolid X_T File Parsing

SiemensParasolid V38.0

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V38.0.235 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-306654

SSA-306654: Insyde BIOS Vulnerabilities in Siemens Industrial Products

SiemensRUGGEDCOM APE1808 - BIOS

Siemens ProductCERThoog

Risk evaluation

Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code

Revisiegeschiedenis (4)
  1. Initiële publicatie22 februari 2022

    Publication Date

  2. Update A8 maart 2022

    Corrected AV:L for all CVEs, added RUGGEDCOM APE1808 and SIMATIC IPC477E PRO

  3. Update B12 juli 2022

    Added CVE-2021-43613, CVE-2021-43614 and CVE-2021-38489, add fix for SIMATIC Field PG M6, SIMATIC ITP1000 for all CVEs except CVE-2021-43613

  4. Update C9 augustus 2022

    Added fix for SIMATIC IPC227G, SIMATIC IPC277G, SIMATIC IPC327G, SIMATIC IPC377G, clarified affected versions for RUGGEDCOM APE1808

Officiële bron: Siemens ProductCERT

SSA-392349

SSA-392349: Denial of Service Vulnerability in Industrial Devices

SiemensIE/PB LINK HA (6GK1411-5BB00)

Siemens ProductCERThoog

Gepubliceerd

12 mei 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead

Revisiegeschiedenis (3)
  1. Initiële publicatie12 mei 2026

    Publication Date

  2. Update A14 juli 2026

    Added fix for SCALANCE SC-600 family

  3. Update B11 augustus 2026

    Added fix for IE/PB LINK HA

Officiële bron: Siemens ProductCERT

SSA-584312

SSA-584312: File Parsing Vulnerabilities in Simcenter Femap Before V2606 MP1

SiemensSimcenter Femap

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2606.0001 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-621657

SSA-621657: File Parsing Vulnerabilities in Solid Edge Before Version SE2026 Update 7

SiemensSolid Edge SE2025

Siemens ProductCERThoog

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V225.0 Update 15 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-628843

SSA-628843: Out of Bound Read Vulnerability in TPM 2.0

SiemensSIMATIC CN 4100

Siemens ProductCERTmiddel

Gepubliceerd

14 april 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Currently no fix is planned

Revisiegeschiedenis (2)
  1. Initiële publicatie14 april 2026

    Publication Date

  2. Update A11 augustus 2026

    Added no fix planned for SIMATIC ITP1000 and for SIMATIC Field PG M5. Added fix for SIMATIC Field PG M6

Officiële bron: Siemens ProductCERT

SSA-686975

SSA-686975: IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs

SiemensSIMATIC Field PG M5

Siemens ProductCERThoog

Gepubliceerd

14 februari 2023

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update ("2022.3 IPU – BIOS Advisory" Intel-SA-00688). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.

Revisiegeschiedenis (4)
  1. Initiële publicatie14 februari 2023

    Publication Date

  2. Update A9 mei 2023

    Added affected products SIMATIC IPC PX-39A and SIMATIC IPC PX-39A pro

  3. Update B11 juli 2023

    Added fix for SIMATIC Field PG M5

  4. Update C8 augustus 2023

    Added fix for SIMATIC IPC BX-39A, SIMATIC IPC PX-39A, and SIMATIC IPC PX-39A pro

Officiële bron: Siemens ProductCERT

SSA-751328

SSA-751328: Recoverable Hardcoded AES Master Key in Siemens LOGO! Soft Comfort

SiemensLOGO! Soft Comfort

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Getroffen sectoren

Risk evaluation

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V9 or later version Note: A hardware upgrade to LOGO! V9 BM or later is also required to avoid compatibility mode, in which the vulnerabilities addressed by this advisory remain present.

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-781903

SSA-781903: Denial of Service Vulnerability in Desigo DXR and PXC Controllers

SiemensDesigo DXR2

Siemens ProductCERTmiddel

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-825228

SSA-825228: Potential Remote Code Execution in Siveillance Video Management Servers

SiemensSiveillance Video V2023 R3

Siemens ProductCERTkritiek

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Mitigatiesamenvatting

Update to V23.3 HotfixRev27 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-827968

SSA-827968: Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERThoog

Risk evaluation

Nozomi Networks has published information on vulnerabilities in Nozomi Guardian/CMC. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigatiesamenvatting

Upgrade Nozomi Guardian to v26.2.0. Contact customer support to receive patch and update information

Revisiegeschiedenis (4)
  1. Initiële publicatie13 januari 2026

    Publication Date

  2. Update A14 april 2026

    Added CVE-2025-40894

  3. Update B12 mei 2026

    Added CVE-2025-40897 and CVE-2025-40899

  4. Update C9 juni 2026

    Added CVE-2025-40900, CVE-2025-40901, CVE-2025-40902, CVE--2025-40903 and CVE-2025-40904

Officiële bron: Siemens ProductCERT

SSA-834709

SSA-834709: Missing Authentication Vulnerability in Node-RED on SIMATIC IoT2050 Advanced with Industrial OS

SiemensSIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2)

Siemens ProductCERTkritiek

Gepubliceerd

11 augustus 2026

Laatste update

11 augustus 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.

Mitigatiesamenvatting

Harden the Node-RED installation (see Node-RED User Guide)

Revisiegeschiedenis (1)
  1. Initiële publicatie11 augustus 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-864900

SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices

SiemensRUGGEDCOM APE1808

Siemens ProductCERTkritiek

Risk evaluation

Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.

Mitigatiesamenvatting

Update Fortigate NGFW to V7.4.9 or later following the secure update recommendation procedure. Contact customer support to receive detailed information

Revisiegeschiedenis (4)
  1. Initiële publicatie13 mei 2025

    Publication Date

  2. Update A8 juli 2025

    Added CVE-2025-24471, CVE-2025-22862, CVE-2024-50562 and CVE-2025-25250

  3. Update B12 augustus 2025

    Added CVE-2024-55599

  4. Update C9 september 2025

    Added CVE-2025-25248 and CVE-2025-53744

Officiële bron: Siemens ProductCERT

ICSA-26-209-04

Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-28531CVE-2023-51384CVE-2023-52927CVE-2024-26783CVE-2024-27056CVE-2024-28956CVE-2024-36903CVE-2024-36927CVE-2024-42079CVE-2024-46786CVE-2024-47736CVE-2024-47809CVE-2024-49968CVE-2024-49994CVE-2024-49998CVE-2024-50014CVE-2024-50063CVE-2024-50164CVE-2024-50298CVE-2024-53124CVE-2024-53170CVE-2024-54458CVE-2024-56631CVE-2024-56703CVE-2024-56719CVE-2024-57917CVE-2024-57924CVE-2024-57973CVE-2024-57977CVE-2024-57979CVE-2024-58011CVE-2024-58016CVE-2024-58020CVE-2024-58056CVE-2024-58058CVE-2024-58061CVE-2024-58086CVE-2025-21645CVE-2025-21648CVE-2025-21655CVE-2025-21676CVE-2025-21682CVE-2025-21702CVE-2025-21705CVE-2025-21706CVE-2025-21707CVE-2025-21718CVE-2025-21731CVE-2025-21745CVE-2025-21758CVE-2025-21760CVE-2025-21764CVE-2025-21765CVE-2025-21780CVE-2025-21795CVE-2025-21796CVE-2025-21802CVE-2025-21814CVE-2025-21846CVE-2025-21853CVE-2025-21861CVE-2025-21864CVE-2025-21867CVE-2025-21875CVE-2025-21887CVE-2025-21913CVE-2025-21919CVE-2025-21925CVE-2025-21926CVE-2025-21938CVE-2025-21959CVE-2025-21999CVE-2025-22005CVE-2025-22015CVE-2025-22055CVE-2025-22056CVE-2025-22060CVE-2025-22083CVE-2025-22090CVE-2025-22095CVE-2025-22107CVE-2025-22111CVE-2025-22121CVE-2025-23136CVE-2025-23143CVE-2025-37785CVE-2025-37909CVE-2025-37917CVE-2025-37945CVE-2025-37959CVE-2025-37964CVE-2025-37972CVE-2025-37980CVE-2025-38125CVE-2025-38162CVE-2025-38192CVE-2025-38201CVE-2025-38232CVE-2025-38322CVE-2025-38591CVE-2025-38614CVE-2025-38681CVE-2025-38704CVE-2025-38721CVE-2025-38725CVE-2025-38727CVE-2025-38732CVE-2025-38736CVE-2025-39681CVE-2025-39691CVE-2025-39721CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39782CVE-2025-39795CVE-2025-39826CVE-2025-39827CVE-2025-39845CVE-2025-39866CVE-2025-39871CVE-2025-39931CVE-2025-39953CVE-2025-39955CVE-2025-39964CVE-2025-39977CVE-2025-39978CVE-2025-39980CVE-2025-40022CVE-2025-40070CVE-2025-40078CVE-2025-40080CVE-2025-40105CVE-2025-40135CVE-2025-40149CVE-2025-40219CVE-2025-40261CVE-2025-40300CVE-2025-61984CVE-2025-61985CVE-2025-68206CVE-2025-68261CVE-2025-68264CVE-2025-68265CVE-2025-68266CVE-2025-68291CVE-2025-68337CVE-2025-68349CVE-2025-68363CVE-2025-68371CVE-2025-68724CVE-2025-68725CVE-2025-68742CVE-2025-68764CVE-2025-68773CVE-2025-68776CVE-2025-68782CVE-2025-68787CVE-2025-68788CVE-2025-68798CVE-2025-68803CVE-2025-68814CVE-2025-68816CVE-2025-68818CVE-2025-68820CVE-2025-71064CVE-2025-71075CVE-2025-71079CVE-2025-71085CVE-2025-71086CVE-2025-71088CVE-2025-71095CVE-2025-71097CVE-2025-71098CVE-2025-71104CVE-2025-71112CVE-2025-71113CVE-2025-71114CVE-2025-71120CVE-2025-71123CVE-2025-71131CVE-2025-71161CVE-2025-71162CVE-2025-71163CVE-2025-71185CVE-2025-71186CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2025-71197CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3497CVE-2026-22977CVE-2026-22979CVE-2026-22980CVE-2026-22982CVE-2026-22992CVE-2026-22994CVE-2026-23003CVE-2026-23005CVE-2026-23010CVE-2026-23011CVE-2026-23019CVE-2026-23026CVE-2026-23038CVE-2026-23054CVE-2026-23060CVE-2026-23083CVE-2026-23084CVE-2026-23086CVE-2026-23087CVE-2026-23095CVE-2026-23100CVE-2026-23103CVE-2026-23110CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-27135CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-40355CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-46174CVE-2026-46300CVE-2026-46333

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-019113 advisory

Officiële bron: CISA

ICSA-26-209-03

Siemens SIMATIC S7-PLCSIM Advanced

SiemensSIMATIC S7-PLCSIM Advanced

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-828211 advisory

Officiële bron: CISA

ICSA-26-209-02

Siemens Mendix Runtime

SiemensMendix Runtime

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation.

Mitigatiesamenvatting

Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-814963 advisory

Officiële bron: CISA

ICSA-26-209-01

Siemens Desigo CC

SiemensDesigo CC family V7

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

28 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Currently no fix is available

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A28 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-734552 advisory

Officiële bron: CISA

ICSA-26-202-06

Siemens CADRA

SiemensCADRA

CISAkritiek

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V2511 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-470355 advisory

Officiële bron: CISA

ICSA-26-202-05

Siemens IAM Client

SiemensCOMOS V10.4.5

CISAmiddel

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V10.6.1 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-288252 advisory

Officiële bron: CISA

ICSA-26-202-04

Siemens SIDIS Secured SmartPlug

SiemensSIDIS Secured SmartPlug

CISAkritiek

Risk evaluation

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V7.26.0310 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-585531 advisory

Officiële bron: CISA

ICSA-26-202-03

Siemens Opcenter X

SiemensOpcenter X

CISAkritiek

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2604 or later version

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-096828 advisory

Officiële bron: CISA

ICSA-26-202-02

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

SiemensRUGGEDCOM APE1808

CISAhoog

Gepubliceerd

14 juli 2026

Laatste update

21 juli 2026

Getroffen sectoren

Risk evaluation

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

Mitigatiesamenvatting

Contact customer support to receive patch and update information

Revisiegeschiedenis (2)
  1. Initiële publicatie14 juli 2026

    Publication Date

  2. Update A21 juli 2026

    Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory

Officiële bron: CISA

SSA-082556

SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5

SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)

Siemens ProductCERTkritiek

Gepubliceerd

10 juni 2025

Laatste update

14 juli 2026

Gekoppelde CVE's

CVE-2021-41617CVE-2023-4527CVE-2023-4806CVE-2023-4911CVE-2023-5363CVE-2023-6246CVE-2023-6779CVE-2023-6780CVE-2023-28531CVE-2023-38545CVE-2023-38546CVE-2023-44487CVE-2023-46218CVE-2023-46219CVE-2023-48795CVE-2023-51384CVE-2023-51385CVE-2023-52927CVE-2024-2961CVE-2024-6119CVE-2024-6387CVE-2024-12133CVE-2024-12243CVE-2024-24855CVE-2024-26596CVE-2024-28085CVE-2024-33599CVE-2024-33600CVE-2024-33601CVE-2024-33602CVE-2024-34397CVE-2024-37370CVE-2024-37371CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-47736CVE-2024-47809CVE-2024-49998CVE-2024-50246CVE-2024-50298CVE-2024-53166CVE-2024-56719CVE-2024-57924CVE-2024-57977CVE-2024-57996CVE-2024-58005CVE-2025-3198CVE-2025-4373CVE-2025-4598CVE-2025-5244CVE-2025-5245CVE-2025-6395CVE-2025-7425CVE-2025-7545CVE-2025-7546CVE-2025-8224CVE-2025-9230CVE-2025-9232CVE-2025-11082CVE-2025-11083CVE-2025-11412CVE-2025-11413CVE-2025-11414CVE-2025-11494CVE-2025-11495CVE-2025-11839CVE-2025-11840CVE-2025-21676CVE-2025-21682CVE-2025-21701CVE-2025-21702CVE-2025-21712CVE-2025-21724CVE-2025-21728CVE-2025-21745CVE-2025-21756CVE-2025-21758CVE-2025-21765CVE-2025-21766CVE-2025-21767CVE-2025-21795CVE-2025-21796CVE-2025-21848CVE-2025-21862CVE-2025-21864CVE-2025-21865CVE-2025-26465CVE-2025-31115CVE-2025-32988CVE-2025-32989CVE-2025-37945CVE-2025-37980CVE-2025-38058CVE-2025-38063CVE-2025-38067CVE-2025-38071CVE-2025-38079CVE-2025-38083CVE-2025-38100CVE-2025-38111CVE-2025-38124CVE-2025-38162CVE-2025-38167CVE-2025-38192CVE-2025-38198CVE-2025-38201CVE-2025-38212CVE-2025-38214CVE-2025-38215CVE-2025-38222CVE-2025-38231CVE-2025-38236CVE-2025-38280CVE-2025-38285CVE-2025-38312CVE-2025-38342CVE-2025-38350CVE-2025-38364CVE-2025-38393CVE-2025-38400CVE-2025-38430CVE-2025-38451CVE-2025-38457CVE-2025-38465CVE-2025-38466CVE-2025-38468CVE-2025-38470CVE-2025-38471CVE-2025-38477CVE-2025-38498CVE-2025-38499CVE-2025-38614CVE-2025-38685CVE-2025-38691CVE-2025-38701CVE-2025-38702CVE-2025-38704CVE-2025-38708CVE-2025-38721CVE-2025-38724CVE-2025-38727CVE-2025-39683CVE-2025-39689CVE-2025-39697CVE-2025-39724CVE-2025-39748CVE-2025-39756CVE-2025-39764CVE-2025-39770CVE-2025-39773CVE-2025-39783CVE-2025-39787CVE-2025-39795CVE-2025-39798CVE-2025-39866CVE-2025-39929CVE-2025-39931CVE-2025-39977CVE-2025-40022CVE-2025-40135CVE-2025-40219CVE-2025-40261CVE-2025-46836CVE-2025-59375CVE-2025-66382CVE-2025-68206CVE-2025-68265CVE-2025-71161CVE-2025-71221CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2026-3904CVE-2026-4046CVE-2026-4437CVE-2026-4438CVE-2026-5435CVE-2026-5450CVE-2026-5928CVE-2026-6238CVE-2026-23100CVE-2026-23111CVE-2026-23113CVE-2026-23154CVE-2026-23204CVE-2026-23231CVE-2026-23242CVE-2026-23243CVE-2026-23245CVE-2026-23270CVE-2026-23271CVE-2026-23273CVE-2026-23274CVE-2026-23277CVE-2026-23284CVE-2026-23287CVE-2026-23290CVE-2026-23293CVE-2026-23300CVE-2026-23304CVE-2026-23319CVE-2026-23321CVE-2026-23335CVE-2026-23340CVE-2026-23343CVE-2026-23351CVE-2026-23359CVE-2026-23365CVE-2026-23368CVE-2026-23370CVE-2026-23378CVE-2026-23379CVE-2026-23381CVE-2026-23391CVE-2026-23392CVE-2026-23397CVE-2026-23398CVE-2026-23414CVE-2026-23422CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23446CVE-2026-23449CVE-2026-23450CVE-2026-23452CVE-2026-23454CVE-2026-23455CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23463CVE-2026-23474CVE-2026-23475CVE-2026-31389CVE-2026-31391CVE-2026-31396CVE-2026-31402CVE-2026-31403CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31418CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31427CVE-2026-31428CVE-2026-31431CVE-2026-31441CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31466CVE-2026-31469CVE-2026-31485CVE-2026-31494CVE-2026-31495CVE-2026-31496CVE-2026-31503CVE-2026-31504CVE-2026-31507CVE-2026-31508CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31533CVE-2026-31546CVE-2026-31555CVE-2026-31563CVE-2026-31565CVE-2026-31628CVE-2026-31634CVE-2026-31649CVE-2026-31651CVE-2026-31658CVE-2026-31664CVE-2026-31665CVE-2026-31669CVE-2026-31670CVE-2026-31671CVE-2026-31674CVE-2026-31680CVE-2026-31682CVE-2026-31737CVE-2026-31752CVE-2026-31761CVE-2026-31768CVE-2026-32776CVE-2026-32777CVE-2026-32778CVE-2026-40355CVE-2026-41080CVE-2026-41989CVE-2026-43011CVE-2026-43024CVE-2026-43025CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43033CVE-2026-43035CVE-2026-43038CVE-2026-43040CVE-2026-43057CVE-2026-43284CVE-2026-45186CVE-2026-46174CVE-2026-46300

Getroffen sectoren

Risk evaluation

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.

Mitigatiesamenvatting

Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.

Revisiegeschiedenis (4)
  1. Initiële publicatie10 juni 2025

    Publication Date

  2. Update A12 augustus 2025

    Added CVE-2025-6395, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990

  3. Update B13 januari 2026

    Added CVE-2025-66382, CVE-2025-39929, CVE-2025-39931, CVE-2025-39977, CVE-2025-40022, CVE-2025-11082, CVE-2025-11083, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11495, CVE-2025-11839, CVE-2025-11840, CVE-2025-9230, CVE-2025-9232, CVE-2025-3198, CVE-2025-5244, CVE-2025-5245, CVE-2025-7545, CVE-2025-7546, CVE-2025-8224, CVE-2025-7425, CVE-2025-59375

  4. Update C10 februari 2026

    Added 22 CVEs

Officiële bron: Siemens ProductCERT

SSA-096828

SSA-096828: Token Invalidation Vulnerability in Opcenter X Before V2604

SiemensOpcenter X

Siemens ProductCERTkritiek

Gepubliceerd

14 juli 2026

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.

Mitigatiesamenvatting

Update to V2604 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-288252

SSA-288252: Unquoted Search Path Vulnerability in IAM Client

SiemensCOMOS V10.4.5

Siemens ProductCERTmiddel

Gepubliceerd

14 juli 2026

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V10.6.1 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-470355

SSA-470355: Zlib and Foxit Vulnerabilities in CADRA

SiemensCADRA

Siemens ProductCERTkritiek

Risk evaluation

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Mitigatiesamenvatting

Update to V2511 or later version

Revisiegeschiedenis (1)
  1. Initiële publicatie14 juli 2026

    Publication Date

Officiële bron: Siemens ProductCERT

SSA-555707

SSA-555707: Information Disclosure Vulnerability in Simcenter STAR-CCM+

SiemensSimcenter STAR-CCM+

Siemens ProductCERTmiddel

Gepubliceerd

9 augustus 2022

Laatste update

14 juli 2026

Gekoppelde CVE's

Getroffen sectoren

Risk evaluation

Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system's host, user, and display name. Siemens has updated the public Power-on-Demand public license server.

Mitigatiesamenvatting

Avoid using sensitive or personal data in user, host and display names

Revisiegeschiedenis (2)
  1. Initiële publicatie9 augustus 2022

    Publication Date

  2. Update A14 juli 2026

    Added fix for Simcenter STAR-CCM+

Officiële bron: Siemens ProductCERT