Siemens Vulnerabilities and Affected Products
Vulnerabilities associated with SIDIS Secured SmartPlug.
Products
Clear product- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP569 vulnerabilities
- SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP569 vulnerabilities
- SIPLUS S7-1500 CPU 1518-4 PN/DP MFP569 vulnerabilities
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem455 vulnerabilities
- RUGGEDCOM RST2428P276 vulnerabilities
- SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family197 vulnerabilities
- SIMATIC CN 4100186 vulnerabilities
- SCALANCE XCM-/XRM-/XCH-/XRH-300 family179 vulnerabilities
- JT2Go153 vulnerabilities
- Teamcenter Visualization93 vulnerabilities
- RUGGEDCOM APE180880 vulnerabilities
- RUGGEDCOM ROX MX500078 vulnerabilities
- RUGGEDCOM ROX RX140078 vulnerabilities
- RUGGEDCOM ROX RX150078 vulnerabilities
- RUGGEDCOM ROX RX150178 vulnerabilities
- RUGGEDCOM ROX RX151078 vulnerabilities
- RUGGEDCOM ROX RX151178 vulnerabilities
- RUGGEDCOM ROX RX151278 vulnerabilities
- RUGGEDCOM ROX RX152478 vulnerabilities
- RUGGEDCOM ROX RX153678 vulnerabilities
- RUGGEDCOM ROX RX500078 vulnerabilities
- Tecnomatix Plant Simulation V230275 vulnerabilities
- RUGGEDCOM ROX MX5000RE74 vulnerabilities
- TeleControl Server Basic70 vulnerabilities
- SINEC NMS68 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-5121HIGH | Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processingA flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system. CWE-190Mar 30, 2026 | CVSS7.5v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9232MEDIUM | Out-of-bounds read in HTTP client no_proxy handlingIssue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate M… CWE-125Sep 30, 2025 | CVSS5.9v3.1 | EPSS2.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9231MEDIUM | Timing side-channel in SM2 algorithm on 64 bit ARMIssue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly … CWE-385Sep 30, 2025 | CVSS6.5v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9230HIGH | Out-of-bounds read & write in RFC 3211 KEK UnwrapIssue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could… | CVSS7.5v3.1 | EPSS1.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Sudo 1.9.17 Host Option - Elevation of PrivilegeSudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. CWE-863Jun 30, 2025 | CVSS2.8v3.1 | EPSS3.64% | PoCs14 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-5914HIGH | Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.cA vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition. | CVSS7.8v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5222HIGH | Icu: stack buffer overflow in the srbroot::addtag functionA stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. CWE-120May 27, 2025 | CVSS7.0v3.1 | EPSS0.315% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26465MEDIUM | Openssh: machine-in-the-middle attack if verifyhostkeydns is enabledA vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high. CWE-390Feb 18, 2025 | CVSS6.8v3.1 | EPSS7.45% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37660MEDIUM | In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association. CWE-323Feb 11, 2025 | CVSS6.5v3.1 | EPSS0.364% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-48174CRITICAL | There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. CWE-787Aug 22, 2023 | CVSS9.8v3.1 | EPSS3.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-23303CRITICAL | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. CWE-203Jan 17, 2022 | CVSS9.8v3.1 | EPSS3.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-23304CRITICAL | The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. CWE-203Jan 17, 2022 | CVSS9.8v3.1 | EPSS1.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |