ICSA-25-072-03: Siemens SIMATIC S7-1500 TM MFP
CISA advisory · released 2025-03-11
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 3, 2025-09-09 (final)
CISA's summary
Summary: Multiple vulnerabilities have been identified in the BIOS of the SIMATIC S7-1500 TM MFP. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SIMATIC S7-1500 TM MFP - BIOS | vers:all/* |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2024-26982 — CVE-2024-26982 · CWE-125
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check the inode number is not the invalid value of zero
- CVE-2024-41046 — CVE-2024-41046 · CWE-415
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times.
- CVE-2024-41049 — CVE-2024-41049 · CWE-416
In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen.
- CVE-2024-41055 — CVE-2024-41055 · CWE-476
In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section->usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms->usage" to fix a race with section_deactivate() where ms->usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it.
- CVE-2024-42154 — CVE-2024-42154 · CWE-805
In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long, and the policy doesn't have an entry for this attribute at all (neither does it for IPv6 but v6 is manually validated).
- CVE-2024-42161 — CVE-2024-42161 · CWE-457
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD.
- CVE-2024-53124 — CVE-2024-53124 · CWE-362
net: fix data-races around sk sk_forward_alloc.
- CVE-2024-57940 — CVE-2024-57940 · CWE-835
exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that a cluster is linked to itself in the cluster chain, and there is an unused directory entry in the cluster, dentry will not be incremented, causing condition dentry < max_dentries unable to prevent an infinite loop. This infinite loop causes s_lock not to be released, and other tasks will hang, such as exfat_sync_fs().
- CVE-2024-57981 — CVE-2024-57981 · CWE-476
usb: xhci: NULL pointer dereference on certain command aborts. If a command is queued to the final usable TRB of a ring segment, the enqueue pointer is advanced to the subsequent link TRB and no further. If the command is later aborted, when the abort completion is handled the dequeue pointer is advanced to the first TRB of the next segment. If no further commands are queued, xhci_handle_stopped_cmd_ring() sees the ring pointers unequal and assumes that there is a pending command, so it calls xhci_mod_cmd_timer() which crashes if cur_cmd was NULL.
- CVE-2024-58005 — CVE-2024-58005 · CWE-20
tpm: Change to kvalloc() in eventlog/acpi.c.
- CVE-2025-8058 — CVE-2025-8058 · CWE-415
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.
- CVE-2025-21647 — CVE-2025-21647 · CWE-125
In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts
- CVE-2025-21653 — CVE-2025-21653 · CWE-20
net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
- CVE-2025-21678 — CVE-2025-21678 · CWE-20
gtp: Destroy device along with udp socket's netns dismantle
- CVE-2025-21703 — CVE-2025-21703 · CWE-416
netem: Update sch q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses qlen_notify() to maintain its active list.
- CVE-2025-21762 — CVE-2025-21762 · CWE-20
In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
- CVE-2025-21776 — CVE-2025-21776 · CWE-476
USB: hub: Ignore non-compliant devices with too many configs or interfaces. A test program can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer.
- CVE-2025-21806 — CVE-2025-21806 · CWE-20
net: let net.core.dev_weight always be non-zero. The following problem was encountered during stability test: (NULL net_device).
- CVE-2025-21826 — CVE-2025-21826 · CWE-20
netfilter: nf_tables: reject mismatching sum of field_len with set key length. The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.