Siemens ProductCERT security advisories
siemens-productcert · A · active
https://cert-portal.siemens.com/productcert/
Added 2026-09-29: first-party SSA advisories for Siemens OT/ICS (SIMATIC, SCALANCE, SINEC), relevant to civil protection, utilities and building automation in the constituency; CISA ICSA relays arrive later and abridged. RECIPE: `feed https://cert-portal.siemens.com/productcert/rss/advisories.atom 10` (direct; SSA-627195 dated 2026-09-28 at probe), then the SSA HTML or CSAF linked from the item. (2026-09-29 operator-directed setup review)
Cited in 4 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 4).
- CVE-2026-58115; Siemens SIMATIC IoT2050 Advanced ships a Node-RED interface with no authentication, so one unauthenticated HTTP request runs code as root on an OT edge gateway (CVSS 10.0)2026-08-13
- CVE-2025-15467, Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)2026-07-29
- CVE-2025-40948/-40947/-40949, Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root2026-07-18
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)2026-07-10