Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)
Siemens RUGGEDCOM, SCALANCE, SIMATIC NET, and SINEMA Remote Connect products contain input validation and resource management flaws (CWE-400, CWE-20) in network packet handling. An attacker can send specially crafted or excessive network packets that the devices fail to properly validate or rate-limit, causing resource exhaustion and denial of service. This affects industrial communication devices used for networking PLCs, remote I/O modules, wireless connectivity, and remote management. The vulnerability requires only network reachability and no credentials. Siemens recommends updating to patched firmware versions and protecting network access through firewalls and segmentation.
- Network reachability to the affected device (direct or routed)
- No credentials required
- Device running vulnerable firmware version
Patching may require device reboot — plan for process interruption
/api/v1/advisories/2ebd4ff8-c4b9-4e91-9bc2-37211ad787d8