Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-3
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in the firmware of the product.
- Who is affected
- Users of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP with firmware version 3.1.6 or higher.
- Urgency
- Remediation is urgent as the vulnerabilities are actively exploited.
- Action
- Siemens is preparing fix versions and recommends specific countermeasures.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Get an email when a new SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2021-41617Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 83% of all scored CVEs.
- Exploitation confirmedCVE-2023-28531Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 81% of all scored CVEs.
- Exploitation confirmedCVE-2023-51384Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 35% of all scored CVEs.
- Exploitation confirmedCVE-2023-52927Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 23% of all scored CVEs.
- Exploitation confirmedCVE-2024-26783Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 16% of all scored CVEs.
- Exploitation confirmedCVE-2024-27056Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 15% of all scored CVEs.
- Exploitation confirmedCVE-2024-28956Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 30% of all scored CVEs.
- Exploitation confirmedCVE-2024-36903Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 14% of all scored CVEs.
- Exploitation confirmedCVE-2024-36927Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 6% of all scored CVEs.
- Exploitation confirmedCVE-2024-42079Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 19% of all scored CVEs.
- Exploitation confirmedCVE-2024-46786Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
- Exploitation confirmedCVE-2024-47736Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
Referenced CVEs
+305 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesubuntu
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of servicecert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of servicecert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service and nonspecific attackcert-bund
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- low[UPDATE] [low] Linux Kernel: Vulnerability allows denial of servicecert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
More from CISA Cybersecurity Advisories
- criticalSchneider Electric IGSS2026-07-30
- criticalMikroTik RouterOS2026-07-30
- criticalCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs2026-07-30
- criticalMZ Automation lib608702026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30