<?xml version="1.0" encoding="UTF-8"?>
<VrdaData refvuldefversion="1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://vrda.jpcert.or.jp" xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo revisionno="1" lang="ja" invalidated="false">
    <VulinfoID>JVNDB-2026-015487</VulinfoID>
    <VulinfoData>
      <Title>Siemens&#35069;&#21697;&#12395;&#23550;&#12377;&#12427;&#12450;&#12483;&#12503;&#12487;&#12540;&#12488;&#65288;2026&#24180;5&#26376;&#65289;</Title>
      <VulinfoDescription>
        <Overview>&#26032;&#35215;&#65306;18&#20214;SSA-032379: Multiple Vulnerabilities in SIMATIC CN 4100 Before V5.0SSA-078743: Remote Code Execution Vulnerability in Ruggedcom Rox Before V2.17.1SSA-081142: Arbitrary Code Execution Vulnerability in Ruggedcom Rox Before 2.17.1SSA-085541: Missing Authentication in Critical Function in ActiveMQ Artemis (CVE-2026-27446) in Opcenter RDnLSSA-357982: Path Traversal Vulnerability in ROS# Before 2.2.2SSA-387223: Unauthenticated Control Panel Escape Vulnerability on SIMATIC HMI Unified Comfort before V21.0SSA-392349: Denial of Service Vulnerability in Industrial DevicesSSA-545643: Multiple Vulnerabilities in KACO Blueplanet InvertersSSA-577017: Multiple Vulnerabilities in Ruggedcom Rox Before 2.17.1SSA-688146: Multiple Cross-Site Scripting Vulnerabilities in SIMATIC S7 PLCs Web ServerSSA-783943: HTTP Request Smuggling Vulnerability in SENTRON 7KT PAC1261 Data Manager Before V2.1.0SSA-786884: Insufficient Randomness in Session Identifier Vulnerability in SIPROTEC 5SSA-827383: Multiple Vulnerabilities in TeamcenterSSA-870926: Datakit Vulnerability in Simcenter FemapSSA-876049: Prototype Pollution Vulnerability in Axios Library Affecting Siemens gWAP Before V3.1.1SSA-921111: Two File Parsing Vulnerabilities in Solid Edge Before version SE225 Update 5SSA-967325: Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 DevicesSSA-973901: Arbitrary File Disclosure Vulnerability in Ruggedcom Rox Before V2.17.1&#26356;&#26032;&#65306;11&#20214;SSA-001536: Authorization Bypass Vulnerability in Siemens Industrial Edge DevicesSSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGsSSA-265688: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1SSA-280834: Improper OpenVPN Credential Validation Vulnerability in SCALANCE M-800 and SC-600 FamiliesSSB-295699: Configuration of Microsoft Defender Antivirus for SIMATIC PCS 7 and SIMATIC PCS neoSSA-452276: Eval Injection Vulnerability in SIMATIC S7-1500SSA-723487: RADIUS Protocol Susceptible to Forgery Attacks (CVE-2024-3596) - Impact to SCALANCE, RUGGEDCOM and Related ProductsSSA-827968: Vulnerability in Nozomi Guardian/CMC Before V26.2.0 on RUGGEDCOM APE1808 DevicesSSA-904646: Sensitive Data Exposure Vulnerability in SIPROTEC 5 DevicesSSA-975644: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/o:siemens:multiple_product</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
      </FactAnalysis>
      <Related>
        <RelatedItem relationtype="self" origin="jvnipedia">
          <URL>https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-015487.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2024-3596</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2024-3596</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2026-27446</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2026-27446</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>JVN</Name>
          <VulinfoID>JVNVU#99296478</VulinfoID>
          <URL>https://jvn.jp/vu/JVNVU99296478/index.html</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2026-05-14T17:11:25+09:00</DateFirstPublished>
      <DateLastUpdated>2026-05-14T17:11:25+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
