As cited
Copy frozen at (site build).
ot ics
Siemens SIPLUS and SIMATIC Products
Siemens released security advisories for CVE-2026-31431, a Linux kernel vulnerability affecting numerous SIPLUS and SIMATIC product lines including runtime environments, human machine interface panels, and industrial edge devices. The vulnerability enables incorrect resource transfer between security spheres with a CVSS score of 7.8, and Siemens has released patched versions for most affected products while providing mitigation guidance for others.
Why it matters: Organizations running Siemens SIMATIC or SIPLUS industrial control systems and edge devices need to prioritize patching to version 21 Update 2 SR1 or later, as this actively exploited vulnerability allows local privilege escalation on affected Linux-based platforms.
- Source published
- First seen by Cybersecurity Tracker