{"schema_version":1,"title":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 204 vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 1 exploited in the wild. The most recent, CVE-2026-43057, was published on 1 May 2026.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp","json_url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":66,"all_time":204,"critical":10,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":166},"latest":[{"cve":"CVE-2026-43057","cvss":7.5,"epss":0.0037,"slug":"cve-2026-43057-linux-kernel-denial-of-service-in-ipv6-tunneled-traffic-handling","title":"Linux Kernel denial of service in IPv6 tunneled traffic handling","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:52.26+00:00","url":"https://junglewise.ai/threats/cve-2026-43057-linux-kernel-denial-of-service-in-ipv6-tunneled-traffic-handling"},{"cve":"CVE-2026-43040","cvss":7.1,"epss":0.0012,"slug":"cve-2026-43040-linux-kernel-information-leak-in-ipv6-ndisc-nduseroptmsg","title":"Linux Kernel information leak in IPv6 ndisc nduseroptmsg","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:50.13+00:00","url":"https://junglewise.ai/threats/cve-2026-43040-linux-kernel-information-leak-in-ipv6-ndisc-nduseroptmsg"},{"cve":"CVE-2026-43035","cvss":5.5,"epss":0.0012,"slug":"cve-2026-43035-linux-kernel-information-leak-in-tc-chain-fill-node","title":"Linux kernel information leak in tc_chain_fill_node","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:48.147+00:00","url":"https://junglewise.ai/threats/cve-2026-43035-linux-kernel-information-leak-in-tc-chain-fill-node"},{"cve":"CVE-2026-43033","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43033-linux-kernel-memory-corruption-in-crypto-authencesn-decryption","title":"Linux Kernel memory corruption in crypto authencesn decryption","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.91+00:00","url":"https://junglewise.ai/threats/cve-2026-43033-linux-kernel-memory-corruption-in-crypto-authencesn-decryption"},{"cve":"CVE-2026-43030","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43030-linux-kernel-bpf-verifier-incorrect-state-pruning-in-regsafe","title":"Linux Kernel BPF verifier incorrect state pruning in regsafe","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.557+00:00","url":"https://junglewise.ai/threats/cve-2026-43030-linux-kernel-bpf-verifier-incorrect-state-pruning-in-regsafe"},{"cve":"CVE-2026-43028","cvss":7.1,"epss":0.0013,"slug":"cve-2026-43028-linux-kernel-netfilter-missing-null-termination-in-x-tables","title":"Linux Kernel Netfilter missing null-termination in x_tables","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.297+00:00","url":"https://junglewise.ai/threats/cve-2026-43028-linux-kernel-netfilter-missing-null-termination-in-x-tables"},{"cve":"CVE-2026-43027","cvss":7.8,"epss":0.0013,"slug":"cve-2026-43027-linux-kernel-use-after-free-in-netfilter-nf-conntrack-helper","title":"Linux Kernel use-after-free in Netfilter nf_conntrack_helper","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:47.167+00:00","url":"https://junglewise.ai/threats/cve-2026-43027-linux-kernel-use-after-free-in-netfilter-nf-conntrack-helper"},{"cve":"CVE-2026-43026","cvss":5.5,"epss":0.0012,"slug":"cve-2026-43026-linux-kernel-netfilter-uninitialized-memory-use-in-ctnetlink","title":"Linux Kernel Netfilter uninitialized memory use in ctnetlink","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:47.033+00:00","url":"https://junglewise.ai/threats/cve-2026-43026-linux-kernel-netfilter-uninitialized-memory-use-in-ctnetlink"},{"cve":"CVE-2026-43025","cvss":7.3,"epss":0.0013,"slug":"cve-2026-43025-linux-kernel-netfilter-out-of-bounds-read-in-ctnetlink","title":"Linux Kernel Netfilter out-of-bounds read in ctnetlink","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:46.903+00:00","url":"https://junglewise.ai/threats/cve-2026-43025-linux-kernel-netfilter-out-of-bounds-read-in-ctnetlink"},{"cve":"CVE-2026-43024","cvss":5.5,"epss":0.0012,"slug":"cve-2026-43024-linux-kernel-denial-of-service-in-netfilter-nf-tables","title":"Linux Kernel denial of service in netfilter nf_tables","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:46.76+00:00","url":"https://junglewise.ai/threats/cve-2026-43024-linux-kernel-denial-of-service-in-netfilter-nf-tables"},{"cve":"CVE-2026-43011","cvss":9.8,"epss":0.0051,"slug":"cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack","title":"Linux Kernel double free in net/x25 networking stack","severity":"critical","exploited":false,"published_at":"2026-05-01T15:16:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack"},{"cve":"CVE-2026-31768","cvss":7.8,"epss":0.0013,"slug":"cve-2026-31768-linux-kernel-ti-adc161s626-dma-safe-memory-corruption","title":"Linux Kernel ti-adc161s626 DMA-safe memory corruption","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:39.977+00:00","url":"https://junglewise.ai/threats/cve-2026-31768-linux-kernel-ti-adc161s626-dma-safe-memory-corruption"},{"cve":"CVE-2026-31761","cvss":7.8,"epss":0.001,"slug":"cve-2026-31761-linux-kernel-race-condition-in-mpu-3050-gyroscope-driver","title":"Linux Kernel race condition in MPU-3050 gyroscope driver","severity":"high","exploited":false,"published_at":"2026-05-01T15:16:39.153+00:00","url":"https://junglewise.ai/threats/cve-2026-31761-linux-kernel-race-condition-in-mpu-3050-gyroscope-driver"},{"cve":"CVE-2026-31752","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31752-linux-kernel-out-of-bounds-read-in-bridge-nd-option-parsing","title":"Linux Kernel out-of-bounds read in bridge ND option parsing","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:38.09+00:00","url":"https://junglewise.ai/threats/cve-2026-31752-linux-kernel-out-of-bounds-read-in-bridge-nd-option-parsing"},{"cve":"CVE-2026-31737","cvss":5.5,"epss":0.0012,"slug":"cve-2026-31737-linux-kernel-ftgmac100-resource-leak-in-ring-allocation-failure","title":"Linux Kernel ftgmac100 resource leak in ring allocation failure","severity":"medium","exploited":false,"published_at":"2026-05-01T15:16:36.347+00:00","url":"https://junglewise.ai/threats/cve-2026-31737-linux-kernel-ftgmac100-resource-leak-in-ring-allocation-failure"},{"cve":"CVE-2026-5435","cvss":7.3,"epss":0.002,"slug":"cve-2026-5435-gnu-glibc-out-of-bounds-write-in-ns-printrrf-tsig-handling","title":"GNU glibc out-of-bounds write in ns_printrrf TSIG handling","severity":"high","exploited":false,"published_at":"2026-04-28T13:19:22.29+00:00","url":"https://junglewise.ai/threats/cve-2026-5435-gnu-glibc-out-of-bounds-write-in-ns-printrrf-tsig-handling"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"},{"cve":"CVE-2026-31680","cvss":7.8,"epss":0.0012,"slug":"cve-2026-31680-linux-kernel-use-after-free-in-ipv6-flowlabel","title":"Linux Kernel use-after-free in IPv6 flowlabel","severity":"high","exploited":false,"published_at":"2026-04-25T09:16:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-31680-linux-kernel-use-after-free-in-ipv6-flowlabel"},{"cve":"CVE-2026-31674","cvss":7.1,"epss":0.0012,"slug":"cve-2026-31674-linux-kernel-out-of-bounds-access-in-netfilter-ip6t-rt","title":"Linux Kernel out-of-bounds access in netfilter ip6t_rt","severity":"high","exploited":false,"published_at":"2026-04-25T09:16:00.963+00:00","url":"https://junglewise.ai/threats/cve-2026-31674-linux-kernel-out-of-bounds-access-in-netfilter-ip6t-rt"},{"cve":"CVE-2026-31671","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31671-linux-kernel-information-leak-in-xfrm-user-build-report","title":"Linux Kernel information leak in xfrm_user build_report","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:46.903+00:00","url":"https://junglewise.ai/threats/cve-2026-31671-linux-kernel-information-leak-in-xfrm-user-build-report"},{"cve":"CVE-2026-31670","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31670-linux-kernel-memory-exhaustion-in-rfkill-subsystem","title":"Linux Kernel memory exhaustion in rfkill subsystem","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:46.79+00:00","url":"https://junglewise.ai/threats/cve-2026-31670-linux-kernel-memory-exhaustion-in-rfkill-subsystem"},{"cve":"CVE-2026-31669","cvss":9.8,"epss":0.004,"slug":"cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow","title":"Linux Kernel slab-use-after-free in MPTCP IPv6 subflow","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:46.663+00:00","url":"https://junglewise.ai/threats/cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow"},{"cve":"CVE-2026-31665","cvss":7.8,"epss":0.0012,"slug":"cve-2026-31665-linux-kernel-use-after-free-in-netfilter-nft-ct-timeout-object","title":"Linux Kernel use-after-free in Netfilter nft_ct timeout object","severity":"high","exploited":false,"published_at":"2026-04-24T15:16:46.157+00:00","url":"https://junglewise.ai/threats/cve-2026-31665-linux-kernel-use-after-free-in-netfilter-nft-ct-timeout-object"},{"cve":"CVE-2026-31658","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31658-linux-kernel-memory-leak-in-altera-tse-ethernet-driver","title":"Linux Kernel memory leak in Altera TSE Ethernet driver","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:45.337+00:00","url":"https://junglewise.ai/threats/cve-2026-31658-linux-kernel-memory-leak-in-altera-tse-ethernet-driver"},{"cve":"CVE-2026-31651","cvss":5.5,"epss":0.0011,"slug":"cve-2026-31651-linux-kernel-null-pointer-dereference-in-vub300-mmc-driver","title":"Linux Kernel NULL pointer dereference in vub300 MMC driver","severity":"medium","exploited":false,"published_at":"2026-04-24T15:16:44.573+00:00","url":"https://junglewise.ai/threats/cve-2026-31651-linux-kernel-null-pointer-dereference-in-vub300-mmc-driver"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens RUGGEDCOM APE1808","slug":"ruggedcom-ape1808","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/ruggedcom-ape1808"},{"name":"Siemens RUGGEDCOM RST2428P","slug":"ruggedcom-rst2428p","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p"},{"name":"Siemens ROX II","slug":"rox-ii","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rox-ii"},{"name":"Siemens SINEC OS","slug":"sinec-os","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/sinec-os"},{"name":"Siemens Solid Edge","slug":"solid-edge","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/solid-edge"},{"name":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem","slug":"simatic-s7-1500-tm-mfp-gnu-linux-subsystem","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem"},{"name":"Siemens Ruggedcom Rox II","slug":"ruggedcom-rox-ii","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rox-ii"},{"name":"Siemens Reyrolle 7SR5","slug":"reyrolle-7sr5","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/reyrolle-7sr5"},{"name":"Siemens Simcenter Femap","slug":"simcenter-femap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/simcenter-femap"}],"technology":{"hub":true,"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vendor":{"name":"Siemens","slug":"siemens","url":"https://junglewise.ai/threats/vendors/siemens"},"aliases":[],"category":"industrial-automation-hardware","homepage":"https://www.siemens.com/","repo_url":"https://mall.industry.siemens.com/mall/en/WW/Catalog/Product/6ES7518-4AX00-1AC0","description":"A high-end industrial controller with integrated Multi-Functional Platform capabilities for complex automation tasks.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},"most_severe":[{"cve":"CVE-2025-39964","cvss":3.3,"epss":0.01,"slug":"cve-2025-39964-linux-kernel-race-condition-in-af-alg-sendmsg","title":"Linux Kernel race condition in af_alg_sendmsg","severity":"critical","exploited":true,"published_at":"2025-10-13T14:15:34.737+00:00","url":"https://junglewise.ai/threats/cve-2025-39964-linux-kernel-race-condition-in-af-alg-sendmsg"},{"cve":"CVE-2026-43011","cvss":9.8,"epss":0.0051,"slug":"cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack","title":"Linux Kernel double free in net/x25 networking stack","severity":"critical","exploited":false,"published_at":"2026-05-01T15:16:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-43011-linux-kernel-double-free-in-net-x25-networking-stack"},{"cve":"CVE-2026-5450","cvss":9.8,"epss":0.0045,"slug":"cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier","title":"GNU glibc heap buffer overflow in scanf %mc specifier","severity":"critical","exploited":false,"published_at":"2026-04-20T21:16:36.85+00:00","url":"https://junglewise.ai/threats/cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier"},{"cve":"CVE-2026-31649","cvss":9.8,"epss":0.0041,"slug":"cve-2026-31649-linux-kernel-stmmac-integer-underflow-in-jumbo-frm","title":"Linux Kernel stmmac integer underflow in jumbo_frm","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:44.33+00:00","url":"https://junglewise.ai/threats/cve-2026-31649-linux-kernel-stmmac-integer-underflow-in-jumbo-frm"},{"cve":"CVE-2026-31669","cvss":9.8,"epss":0.004,"slug":"cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow","title":"Linux Kernel slab-use-after-free in MPTCP IPv6 subflow","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:46.663+00:00","url":"https://junglewise.ai/threats/cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow"},{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"},{"cve":"CVE-2025-38724","cvss":9.8,"epss":0.0016,"slug":"cve-2025-38724-linux-kernel-nfsd-use-after-free-in-nfsd4-setclientid-confirm","title":"Linux Kernel nfsd use-after-free in nfsd4_setclientid_confirm","severity":"critical","exploited":false,"published_at":"2025-09-04T16:15:42.273+00:00","url":"https://junglewise.ai/threats/cve-2025-38724-linux-kernel-nfsd-use-after-free-in-nfsd4-setclientid-confirm"},{"cve":"CVE-2025-38708","cvss":9.8,"epss":0.0016,"slug":"cve-2025-38708-linux-kernel-use-after-free-in-drbd-handle-write-conflicts","title":"Linux Kernel use after free in DRBD handle_write_conflicts","severity":"critical","exploited":false,"published_at":"2025-09-04T16:15:39.847+00:00","url":"https://junglewise.ai/threats/cve-2025-38708-linux-kernel-use-after-free-in-drbd-handle-write-conflicts"},{"cve":"CVE-2026-31448","cvss":9.4,"epss":0.0043,"slug":"cve-2026-31448-linux-kernel-infinite-loop-in-ext4-file-system-extent-mapping","title":"Linux Kernel infinite loop in ext4 file system extent mapping","severity":"critical","exploited":false,"published_at":"2026-04-22T14:16:38.76+00:00","url":"https://junglewise.ai/threats/cve-2026-31448-linux-kernel-infinite-loop-in-ext4-file-system-extent-mapping"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}