Siemens Vulnerabilities and Affected Products
Vulnerabilities associated with SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP.
Products
Clear product- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP569 vulnerabilities
- SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP569 vulnerabilities
- SIPLUS S7-1500 CPU 1518-4 PN/DP MFP569 vulnerabilities
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem455 vulnerabilities
- RUGGEDCOM RST2428P276 vulnerabilities
- SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family197 vulnerabilities
- SIMATIC CN 4100186 vulnerabilities
- SCALANCE XCM-/XRM-/XCH-/XRH-300 family179 vulnerabilities
- JT2Go153 vulnerabilities
- Teamcenter Visualization93 vulnerabilities
- RUGGEDCOM APE180880 vulnerabilities
- RUGGEDCOM ROX MX500078 vulnerabilities
- RUGGEDCOM ROX RX140078 vulnerabilities
- RUGGEDCOM ROX RX150078 vulnerabilities
- RUGGEDCOM ROX RX150178 vulnerabilities
- RUGGEDCOM ROX RX151078 vulnerabilities
- RUGGEDCOM ROX RX151178 vulnerabilities
- RUGGEDCOM ROX RX151278 vulnerabilities
- RUGGEDCOM ROX RX152478 vulnerabilities
- RUGGEDCOM ROX RX153678 vulnerabilities
- RUGGEDCOM ROX RX500078 vulnerabilities
- Tecnomatix Plant Simulation V230275 vulnerabilities
- RUGGEDCOM ROX MX5000RE74 vulnerabilities
- TeleControl Server Basic70 vulnerabilities
- SINEC NMS68 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-46174HIGH | x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cacheIn the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache Make sure resources are not improperly shared in the op cache and cause instruction corruption this way. May 28, 2026 | CVSS8.8v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-46300HIGH | net: skbuff: preserve shared-frag marker during coalescingIn the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whet… | CVSS7.8v3.1 | EPSS7.01% | PoCs17 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-46333HIGH | ptrace: slightly saner 'get_dumpable()' logicIn the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other thi… CWE-269May 15, 2026 | CVSS7.1v3.1 | EPSS1.5% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25789HIGH | Generated title:Siemens SIMATIC S7-1500 and ET 200SP CPU Firmware Update Page Cross-Site ScriptingAffected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. This would result in malitcious JavaScript execution in the context of the authenticated user's session without requiring the file to be uploaded, potentially leading to session hijacking or credential theft. CWE-79May 12, 2026 | CVSS7.2v4.0 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25787CRITICAL | Generated title:Siemens SIMATIC S7-1500 and ET 200SP CPU Improper Input Validation in Technology Object Name Leading to Stored Cross-Site ScriptingAffected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session. CWE-79May 12, 2026 | CVSS9.3v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25786CRITICAL | Generated title:Siemens SIMATIC S7-1500 and ET 200SP CPU Web Interface Stored Cross-Site ScriptingAffected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session. CWE-79May 12, 2026 | CVSS9.3v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:libexpat Inefficient Algorithmic Complexity Denial of ServiceIn libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. CWE-407May 10, 2026 | CVSS2.9v3.1 | EPSS0.443% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-43284HIGH | xfrm: esp: avoid in-place decrypt on shared skb fragsIn the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking … CWE-123May 8, 2026 | CVSS8.8v3.1 | EPSS93.2% | PoCs47 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43057HIGH | net: correctly handle tunneled traffic on IPV6_CSUM GSO fallbackIn the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming. Since TSO depends on checksum offload, those must revert to GSO. The below commit introduces that fallback. It always checks network header length. For tunneled packets, the inner head… May 1, 2026 | CVSS7.5v3.1 | EPSS0.389% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43040HIGH | net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leakIn the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak When processing Router Advertisements with user options the kernel builds an RTM_NEWNDUSEROPT netlink message. The nduseroptmsg struct has three padding fields that are never zeroed and can leak kernel data The fix is simple, just zeroes the padding fields. CWE-909May 1, 2026 | CVSS7.1v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43038CRITICAL | ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2 and passed to icmp6_send(), it uses IP6CB(skb2). IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso offset in inet_skb_parm.opt directly overlaps with dsthao … CWE-843May 1, 2026 | CVSS9.8v3.1 | EPSS0.255% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43035MEDIUM | net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leakIn the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is not zeroed, kernel heap memory is leaked to userspace through this 4-byte field. The fix simply zeroes tcm_info alongside the other fields that are already initialized. CWE-908May 1, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43033HIGH | crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryptionIn the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks, May 1, 2026 | CVSS7.8v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43030HIGH | bpf: Fix regsafe() for pointers to packetIn the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold->reg->range == BEYOND_PKT_END && rcur->reg->range == N regsafe() may return true which may lead to current state with valid packet range not being explored. Fix the bug. May 1, 2026 | CVSS7.8v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43028HIGH | netfilter: x_tables: ensure names are nul-terminatedIn the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change. May 1, 2026 | CVSS7.1v3.1 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43027HIGH | netfilter: nf_conntrack_helper: pass helper to expect cleanupIn the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy() to remove expectations belonging to the helper being unregistered. However, it passes NULL instead of the helper pointer as the data argument, so expect_iter_me() never matches any expectation and all of them survive the cleanup. After unregister returns, nfnl_cthelper_del() frees the helper obje… CWE-416May 1, 2026 | CVSS7.8v3.1 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43026MEDIUM | netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absentIn the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent ctnetlink_alloc_expect() allocates expectations from a non-zeroing slab cache via nf_ct_expect_alloc(). When CTA_EXPECT_NAT is not present in the netlink message, saved_addr and saved_proto are never initialized. Stale data from a previous slab occupant can then be dumped to userspace by ctnetlink_exp_dump_expect(), which checks these fields to decide wh… May 1, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43025HIGH | netfilter: ctnetlink: ignore explicit helper on new expectationsIn the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ignore explicit helper on new expectations Use the existing master conntrack helper, anything else is not really supported and it just makes validation more complicated, so just ignore what helper userspace suggests for this expectation. This was uncovered when validating CTA_EXPECT_CLASS via different helper provided by userspace than the existing master conntrack helper: BUG: KASAN: slab-out-of-boun… CWE-125May 1, 2026 | CVSS7.3v3.1 | EPSS0.126% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43024MEDIUM | netfilter: nf_tables: reject immediate NF_QUEUE verdictIn the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject immediate NF_QUEUE verdict nft_queue is always used from userspace nftables to deliver the NF_QUEUE verdict. Immediately emitting an NF_QUEUE verdict is never used by the userspace nft tools, so reject immediate NF_QUEUE verdicts. The arp family does not provide queue support, but such an immediate verdict is still reachable. Globally reject NF_QUEUE immediate verdicts to address this issue. May 1, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43011CRITICAL | net/x25: Fix potential double free of skbIn the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_r… CWE-415May 1, 2026 | CVSS9.8v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-31768HIGH | iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] instead of __be16 and __be32 and change the conversion functions appropriately. May 1, 2026 | CVSS7.8v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-31761HIGH | iio: gyro: mpu3050: Move iio_device_register() to correct locationIn the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_register() should be at the end of the probe function to prevent race conditions. Place iio_device_register() at the end of the probe function and place iio_device_unregister() accordingly. CWE-362May 1, 2026 | CVSS7.8v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-31752MEDIUM | bridge: br_nd_send: validate ND option lengthsIn the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address. May 1, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-31737MEDIUM | net: ftgmac100: fix ring allocation unwind on open failureIn the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cl… May 1, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6238MEDIUM | Buffer overread in ns_printrrf with corrupted RDATA fieldThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they hav… CWE-126Apr 28, 2026 | CVSS6.5v3.1 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |