By vendor
Siemens vulnerabilities
Known CVEs affecting Siemens products, prioritized by severity, with SEC.co remediation and detection guidance.
5 published vulnerabilities
- CVE-2026-46746HIGH 8.8
SINEC INS, a Siemens industrial networking application, contains a command injection vulnerability in its file upload functionality. An authenticated user can craft malicious directory names that bypass input validation, plant shell commands, and trigger their execution when the application later retrieves directory listings. The attacker gains command execution at the privilege level of the service account, potentially compromising the entire system. All versions before 1.0 SP2 Update 6 are affected.
- CVE-2026-46748HIGH 8.8
CVE-2026-46748 affects Siemens SINEC INS installations running versions prior to V1.0 SP2 Update 6. A binary within the system has been granted excessive Linux kernel capabilities (specifically cap_dac_override), which allows it to bypass normal file permission checks. A local attacker who gains access to the system can exploit this to read, modify, or delete any file and escalate privileges to root, gaining complete control of the host. This is a serious flaw in privilege isolation that compounds the risk of any initial compromise.
- CVE-2026-46749HIGH 7.5
SINEC INS, Siemens' industrial networking and security solution, contains a password storage flaw that makes user credentials vulnerable to attack. The system uses the same password salt for every user across all installations, and applies too few computational iterations during hashing. This combination allows an attacker with local system access to crack passwords much faster than intended, potentially gaining unauthorized control of the application.
- CVE-2026-24349HIGH 7.1
A vulnerability in Siemens SIMATIC WinCC Unified PC Runtime allows an attacker with local access to extract sensitive cryptographic material from the Certificate Manager component. The issue stems from inadequate protection of key material stored on disk or in memory, potentially exposing certificates and private keys that protect SCADA/HMI communications. While exploitation requires local system access, the impact is significant because certificate compromise can enable downstream attacks on industrial control systems and their communications.
- CVE-2026-46747MEDIUM 4.3
SINEC INS, Siemens' network security appliance, contains a path traversal vulnerability in its file upload API endpoint. An authenticated user can craft malicious directory paths to access files outside their intended scope on the server. The vulnerability affects all versions prior to V1.0 SP2 Update 6 and requires valid login credentials to exploit, limiting but not eliminating risk in environments where account compromise or insider threats are concerns.