Siemens ProductCERT (CSAF advisory portal)
siemens-productcert-csaf · A · candidate
https://cert-portal.siemens.com/productcert/csaf/
Siemens' own machine-readable CSAF advisory portal — first-party PSIRT authority for Desigo CC, SIMATIC, RUGGEDCOM, SICAM, Mendix and the rest of the Siemens OT/industrial estate. Added 2026-07-29 as this run's one new candidate: two prior published entries in the trailing 30 days cite cert-portal.siemens.com (the SICAM 8 firmware-signing advisory of 2026-07-10 and the RUGGEDCOM ROX II chain of 2026-07-18), with this run's own Desigo CC entry making a third, and the pipeline currently reaches Siemens advisories only through CISA's ICS republication, which lagged Siemens' own publication by two weeks on SSA-734552/SSA-814963 (Siemens 2026-07-14, CISA 2026-07-28). FETCH -> per-advisory structured CSAF: python3 tools/fetch_source.py url https://cert-portal.siemens.com/productcert/csaf/ssa-NNNNNN.json (verified working 2026-07-29). Read affected/fixed from product_status + remediations, never the prose summary. Reliability A: vendor PSIRT for its own products.
Cited in 3 entries
Citation cadence
Citation days per ISO week (4 weeks of coverage span, total 3).
- CVE-2025-15467 — Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)2026-07-29
- CVE-2025-40948/-40947/-40949 — Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root2026-07-18
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)2026-07-10