12 maja 2026 r. firma Siemens opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach następujących produktów. Uwzględniono aktualizacje dla następujących produktów:

  • Rodzina RUGGEDCOM ROX II – wersje wcześniejsze niż V2.17.1
  • RUGGEDCOM APE1808 – skontaktuj się z obsługą klienta, aby uzyskać informacje o poprawkach i aktualizacjach
  • RUGGEDCOM RM1224 LTE(4G) EU – wersje wcześniejsze niż V8.3
  • SCALANCE – wiele wersji i modeli
  • Solid Edge SE2026 – wersje wcześniejsze niż V226.0 Update 5
  • gWAP – wersje wcześniejsze niż V3.1.1
  • Simcenter Femap – wersje wcześniejsze niż V2512.0003
  • Teamcenter – wiele wersji i modeli
  • SIPROTEC 5 – wiele wersji i modeli
  • SENTRON 7KT PAC1261 Data Manager – wersje wcześniejsze niż V2.1.0
  • Rodzina sterowników napędów SIMATIC – wersje wcześniejsze niż V3.1.6
  • SIMATIC Drive Controller CPU 1504D TF – wersje wcześniejsze niż V3.1.6
  • SIMATIC ET 200SP CPU – Wiele wersji i modeli
  • Procesor SIMATIC S7-1500 – wersje starsze niż V2.9.9
  • Falowniki KACO blueplanet – wersje starsze niż V6.1.4.9
  • Urządzenia przemysłowe Edge – wiele wersji i modeli
  • Rodzina paneli SIMATIC HMI Unified Comfort Hygienic – wersje starsze niż V21
  • Rodzina paneli SIMATIC HMI Unified Comfort Standard – wersje starsze niż V21
  • ROS# – wersje starsze niż V2.2.2
  • Opcenter RDnL – wersje starsze niż V2.52.0
  • SIMATIC CN 4100 – wersje starsze niż V5.0
SSA-9756449.8Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-9739016.8Arbitrary File Disclosure Vulnerability in Ruggedcom Rox Before V2.17.1
SSA-96732510Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices
SSA-9211117.8Two File Parsing Vulnerabilities in Solid Edge Before version SE225 AKTUALIZACJA 5
SSA-9046465.3Sensitive Data Exposure Vulnerability in SIPROTEC 5 Devices AKTUALIZACJA
SSA-8760498.0Prototype Pollution Vulnerability in Axios Library Affecting Siemens gWAP Before V3.1.1
SSA-8709267.8Datakit Vulnerability in Simcenter Femap
SSA-8279688.9Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-8273837.5Multiple Vulnerabilities in Teamcenter
SSA-7868845.3Insufficient Randomness in Session Identifier Vulnerability in SIPROTEC 5
SSA-7839439.1HTTP Request Smuggling Vulnerability in SENTRON 7KT PAC1261 Data Manager Before V2.1.0
SSA-7234879.0RADIUS Protocol Susceptible to Forgery Attacks (CVE-2024-3596) – Impact to SCALANCE, RUGGEDCOM and Related Products AKTUALIZACJA
SSA-6881469.1Multiple Cross-Site Scripting Vulnerabilities in SIMATIC S7 PLCs Web Server
SSA-5770179.8Multiple Vulnerabilities in Ruggedcom Rox Before 2.17.1
SSA-5456438.3Multiple Vulnerabilities in KACO Blueplanet Inverters
SSA-4522769.6Eval Injection Vulnerability in SIMATIC S7-1500 AKTUALIZACJA
SSA-3923497.5Denial of Service Vulnerability in Industrial Devices
SSA-3872237.7Unauthenticated Control Panel Escape Vulnerability on SIMATIC HMI Unified Comfort before V21.0
SSA-3579829.1Path Traversal Vulnerability in ROS# Before 2.2.2
SSB-295699n/aConfiguration of Microsoft Defender Antivirus for SIMATIC PCS 7 and SIMATIC PCS neo AKTUALIZACJA
SSA-2808343.7Improper OpenVPN Credential Validation Vulnerability in SCALANCE M-800 and SC-600 Families AKTUALIZACJA
SSA-2656889.1Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1 AKTUALIZACJA
SSA-2160148.2Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs AKTUALIZACJA
SSA-0855419.8Missing Authentication in Critical Function in ActiveMQ Artemis (CVE-2026-27446) in Opcenter RDnL
SSA-0825569.8Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5 AKTUALIZACJA
SSA-0811429.1Arbitrary Code Execution Vulnerability in Ruggedcom Rox Before 2.17.1
SSA-0787437.5Remote Code Execution Vulnerability in Ruggedcom Rox Before V2.17.1
SSA-0323799.6Multiple Vulnerabilities in SIMATIC CN 4100 Before V5.0
SSA-00153610Authorization Bypass Vulnerability in Siemens Industrial Edge Devices AKTUALIZACJA