CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens producten

unknownknown exploitedpublic exploitCVE-2024-42384CVE-2024-42385CVE-2024-42386CVE-2024-42391CVE-2024-42392CVE-2024-56181
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Siemens heeft kwetsbaarheden verholpen in diverse producten als Desigo, Reyrolle, SIMATIC, SCALANCE, SINAMICS en Siveillance. De kwetsbaarheden stellen een kwaadwillende in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Manipulatie van gegevens * Omzeilen van een beveiligingsmaatregel * (Remote) code execution (root/admin rechten) * (Remote) code execution (gebruikersrechten) * Toegang tot gevoelige gegevens * Verhogen van rechten De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-09-08
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0346

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-42384coverage & exploitation statusNVD · CVE.org
CVE-2024-42385coverage & exploitation statusNVD · CVE.org
CVE-2024-42386coverage & exploitation statusNVD · CVE.org
CVE-2024-42391coverage & exploitation statusNVD · CVE.org
CVE-2024-42392coverage & exploitation statusNVD · CVE.org
CVE-2024-56181coverage & exploitation statusNVD · CVE.org
CVE-2024-56182coverage & exploitation statusNVD · CVE.org
CVE-2025-15467coverage & exploitation statusNVD · CVE.org
CVE-2025-30033coverage & exploitation statusNVD · CVE.org
CVE-2025-40572coverage & exploitation statusNVD · CVE.org
CVE-2025-40573coverage & exploitation statusNVD · CVE.org
CVE-2025-40574coverage & exploitation statusNVD · CVE.org
CVE-2025-40575coverage & exploitation statusNVD · CVE.org
CVE-2025-40576coverage & exploitation statusNVD · CVE.org
CVE-2025-40577coverage & exploitation statusNVD · CVE.org
CVE-2025-40578coverage & exploitation statusNVD · CVE.org
CVE-2025-40579coverage & exploitation statusNVD · CVE.org
CVE-2025-40580coverage & exploitation statusNVD · CVE.org
CVE-2025-40581coverage & exploitation statusNVD · CVE.org
CVE-2025-40582coverage & exploitation statusNVD · CVE.org
CVE-2025-40583coverage & exploitation statusNVD · CVE.org
CVE-2025-47809coverage & exploitation statusNVD · CVE.org
CVE-2026-18963coverage & exploitation statusNVD · CVE.org
CVE-2026-31431coverage & exploitation statusNVD · CVE.org
CVE-2026-34223coverage & exploitation statusNVD · CVE.org
CVE-2026-50093coverage & exploitation statusNVD · CVE.org
CVE-2026-54798coverage & exploitation statusNVD · CVE.org
CVE-2026-54799coverage & exploitation statusNVD · CVE.org
CVE-2026-54800coverage & exploitation statusNVD · CVE.org
CVE-2026-54801coverage & exploitation statusNVD · CVE.org
CVE-2026-58113coverage & exploitation statusNVD · CVE.org
CVE-2026-62645coverage & exploitation statusNVD · CVE.org
CVE-2026-62646coverage & exploitation statusNVD · CVE.org
CVE-2026-62647coverage & exploitation statusNVD · CVE.org
CVE-2026-62648coverage & exploitation statusNVD · CVE.org
CVE-2026-62649coverage & exploitation statusNVD · CVE.org
CVE-2026-62650coverage & exploitation statusNVD · CVE.org
CVE-2026-62652coverage & exploitation statusNVD · CVE.org
CVE-2026-62653coverage & exploitation statusNVD · CVE.org
CVE-2026-62654coverage & exploitation statusNVD · CVE.org
CVE-2026-67367coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Kwetsbaarheden verholpen in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories