<?xml version="1.0" encoding="UTF-8"?>
<VrdaData refvuldefversion="1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://vrda.jpcert.or.jp" xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo revisionno="1" lang="ja" invalidated="false">
    <VulinfoID>JVNDB-2026-011246</VulinfoID>
    <VulinfoData>
      <Title>Siemens&#35069;&#21697;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;&#65288;2026&#24180;4&#26376;&#65289;</Title>
      <VulinfoDescription>
        <Overview>&#26032;&#35215;&#65306;8&#20214;SSA-019200: Multiple Vulnerabilities in SCALANCE W-700 IEEE 802.11n Devices Before V6.6.0SSA-225816: Memory Corruption Vulnerability in RUGGEDCOM CROSSBOW Station Access Controller Before V5.8SSA-605717: Authorization Bypass Vulnerability in SINEC NMS Before V4.0 SP3SSA-609469: Authorization Bypass Vulnerability in Industrial Edge ManagementSSA-628843: Out of Bound Read Vulnerability in TPM 2.0SSA-741509: Privilege Escalation Vulnerability in RUGGEDCOM CROSSBOW Secure Access Manager Primary Before V5.8SSA-801704: Authentication Bypass Vulnerability in SINEC NMSSSA-981622: Improper Certificate Validation Vulnerability in Siemens Analytics Toolkit&#26356;&#26032;&#65306;13&#20214;SSA-186293: XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT, SIMOTION SCOUT TIA and SINAMICS STARTERSSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGsSSA-244969: OpenSSL Vulnerability in Industrial ProductsSSA-311973: Multiple Local Privilege Escalation Vulnerabilities in SINEC NMS and User Management Component (UMC)SSA-408105: Buffer Overflow Vulnerabilities in OpenSSL 3.0 Affecting Siemens ProductsSSA-552702: Privilege Escalation Vulnerability in the Web Interface of SCALANCE and RUGGEDCOM ProductsSSA-599968: Denial of Service Vulnerability in Profinet DevicesSSA-710008: Multiple Web Vulnerabilities in SCALANCE ProductsSSA-712929: Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial ProductsSSA-726617: Incorrect Privilege Assignment Vulnerability in Mendix OIDC SSO ModuleSSA-726834: Denial of Service Vulnerability in the RADIUS Client of SIPROTEC 5 DevicesSSA-827968: Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 DevicesSSA-913875: Frame Aggregation and Fragmentation Vulnerabilities in 802.11</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/o:siemens:multiple_product</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
      </FactAnalysis>
      <Related>
        <RelatedItem relationtype="self" origin="jvnipedia">
          <URL>https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-011246.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2022-0778</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2022-0778</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>JVN</Name>
          <VulinfoID>JVNVU#93197226</VulinfoID>
          <URL>https://jvn.jp/vu/JVNVU93197226/index.html</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2026-04-16T18:03:01+09:00</DateFirstPublished>
      <DateLastUpdated>2026-04-16T18:03:01+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
