{"schema_version":1,"title":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-28390, was published on 7 April 2026.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem","json_url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":11,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":3},"latest":[{"cve":"CVE-2026-28390","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28389","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.03+00:00","url":"https://junglewise.ai/threats/cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2023-50781","cvss":7.5,"epss":0.0112,"slug":"cve-2023-50781-m2crypto-bleichenbacher-timing-attack-in-rsa-decryption-api","title":"m2crypto Bleichenbacher timing attack in RSA decryption API","severity":"high","exploited":false,"published_at":"2024-02-05T21:15:10.97+00:00","url":"https://junglewise.ai/threats/cve-2023-50781-m2crypto-bleichenbacher-timing-attack-in-rsa-decryption-api"},{"cve":"CVE-2024-24857","cvss":4.6,"slug":"cve-2024-24857-linux-kernel-race-condition-in-bluetooth-device-driver","title":"Linux Kernel race condition in Bluetooth device driver","severity":"medium","exploited":false,"published_at":"2024-02-05T08:15:44.533+00:00","url":"https://junglewise.ai/threats/cve-2024-24857-linux-kernel-race-condition-in-bluetooth-device-driver"},{"cve":"CVE-2024-23307","cvss":4.4,"slug":"cve-2024-23307-linux-kernel-integer-overflow-in-raid5-cache-count","title":"Linux Kernel integer overflow in raid5_cache_count","severity":"medium","exploited":false,"published_at":"2024-01-25T07:15:09.94+00:00","url":"https://junglewise.ai/threats/cve-2024-23307-linux-kernel-integer-overflow-in-raid5-cache-count"},{"cve":"CVE-2024-23848","cvss":5.5,"slug":"cve-2024-23848-linux-kernel-use-after-free-in-cec-framework","title":"Linux Kernel use-after-free in CEC framework","severity":"medium","exploited":false,"published_at":"2024-01-23T09:15:35.957+00:00","url":"https://junglewise.ai/threats/cve-2024-23848-linux-kernel-use-after-free-in-cec-framework"},{"cve":"CVE-2023-1652","cvss":7.1,"slug":"cve-2023-1652-linux-kernel-use-after-free-in-nfs-nfsd4-ssc-setup-dul","title":"Linux Kernel use-after-free in NFS nfsd4_ssc_setup_dul","severity":"high","exploited":false,"published_at":"2023-03-29T21:15:07.997+00:00","url":"https://junglewise.ai/threats/cve-2023-1652-linux-kernel-use-after-free-in-nfs-nfsd4-ssc-setup-dul"},{"cve":"CVE-2022-43945","cvss":7.5,"slug":"cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling","title":"Linux Kernel NFSD buffer overflow in RPC handling","severity":"high","exploited":false,"published_at":"2022-11-04T19:15:11.18+00:00","url":"https://junglewise.ai/threats/cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling"},{"cve":"CVE-2022-38096","cvss":6.3,"slug":"cve-2022-38096-linux-kernel-null-pointer-dereference-in-vmwgfx-driver","title":"Linux Kernel NULL pointer dereference in vmwgfx driver","severity":"medium","exploited":false,"published_at":"2022-09-09T15:15:14.407+00:00","url":"https://junglewise.ai/threats/cve-2022-38096-linux-kernel-null-pointer-dereference-in-vmwgfx-driver"},{"cve":"CVE-2021-4090","cvss":7.1,"slug":"cve-2021-4090-linux-kernel-nfsd-out-of-bounds-write-in-nfsd4-decode-bitmap4","title":"Linux Kernel NFSD out-of-bounds write in nfsd4_decode_bitmap4","severity":"high","exploited":false,"published_at":"2022-02-18T18:15:10.207+00:00","url":"https://junglewise.ai/threats/cve-2021-4090-linux-kernel-nfsd-out-of-bounds-write-in-nfsd4-decode-bitmap4"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens RUGGEDCOM APE1808","slug":"ruggedcom-ape1808","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/ruggedcom-ape1808"},{"name":"Siemens RUGGEDCOM RST2428P","slug":"ruggedcom-rst2428p","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p"},{"name":"Siemens ROX II","slug":"rox-ii","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rox-ii"},{"name":"Siemens SINEC OS","slug":"sinec-os","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/sinec-os"},{"name":"Siemens Solid Edge","slug":"solid-edge","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/solid-edge"},{"name":"Siemens Ruggedcom Rox II","slug":"ruggedcom-rox-ii","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rox-ii"},{"name":"Siemens Reyrolle 7SR5","slug":"reyrolle-7sr5","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/reyrolle-7sr5"},{"name":"Siemens Simcenter Femap","slug":"simcenter-femap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/simcenter-femap"}],"technology":{"hub":true,"name":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem","slug":"simatic-s7-1500-tm-mfp-gnu-linux-subsystem","vendor":{"name":"Siemens","slug":"siemens","url":"https://junglewise.ai/threats/vendors/siemens"},"aliases":[],"category":"firmware","homepage":"https://www.siemens.com/global/en/products/automation/systems/industrial/simatic-s7-1500.html","description":"A Linux-based subsystem for the SIMATIC S7-1500 Technology Module MultiFunctional Platform, enabling the execution of C/C++ and other high-level language applications.","url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem"},"most_severe":[{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2023-50781","cvss":7.5,"epss":0.0112,"slug":"cve-2023-50781-m2crypto-bleichenbacher-timing-attack-in-rsa-decryption-api","title":"m2crypto Bleichenbacher timing attack in RSA decryption API","severity":"high","exploited":false,"published_at":"2024-02-05T21:15:10.97+00:00","url":"https://junglewise.ai/threats/cve-2023-50781-m2crypto-bleichenbacher-timing-attack-in-rsa-decryption-api"},{"cve":"CVE-2026-28390","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28389","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.03+00:00","url":"https://junglewise.ai/threats/cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2022-43945","cvss":7.5,"slug":"cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling","title":"Linux Kernel NFSD buffer overflow in RPC handling","severity":"high","exploited":false,"published_at":"2022-11-04T19:15:11.18+00:00","url":"https://junglewise.ai/threats/cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling"},{"cve":"CVE-2023-1652","cvss":7.1,"slug":"cve-2023-1652-linux-kernel-use-after-free-in-nfs-nfsd4-ssc-setup-dul","title":"Linux Kernel use-after-free in NFS nfsd4_ssc_setup_dul","severity":"high","exploited":false,"published_at":"2023-03-29T21:15:07.997+00:00","url":"https://junglewise.ai/threats/cve-2023-1652-linux-kernel-use-after-free-in-nfs-nfsd4-ssc-setup-dul"},{"cve":"CVE-2021-4090","cvss":7.1,"slug":"cve-2021-4090-linux-kernel-nfsd-out-of-bounds-write-in-nfsd4-decode-bitmap4","title":"Linux Kernel NFSD out-of-bounds write in nfsd4_decode_bitmap4","severity":"high","exploited":false,"published_at":"2022-02-18T18:15:10.207+00:00","url":"https://junglewise.ai/threats/cve-2021-4090-linux-kernel-nfsd-out-of-bounds-write-in-nfsd4-decode-bitmap4"},{"cve":"CVE-2022-38096","cvss":6.3,"slug":"cve-2022-38096-linux-kernel-null-pointer-dereference-in-vmwgfx-driver","title":"Linux Kernel NULL pointer dereference in vmwgfx driver","severity":"medium","exploited":false,"published_at":"2022-09-09T15:15:14.407+00:00","url":"https://junglewise.ai/threats/cve-2022-38096-linux-kernel-null-pointer-dereference-in-vmwgfx-driver"},{"cve":"CVE-2024-23848","cvss":5.5,"slug":"cve-2024-23848-linux-kernel-use-after-free-in-cec-framework","title":"Linux Kernel use-after-free in CEC framework","severity":"medium","exploited":false,"published_at":"2024-01-23T09:15:35.957+00:00","url":"https://junglewise.ai/threats/cve-2024-23848-linux-kernel-use-after-free-in-cec-framework"},{"cve":"CVE-2024-24857","cvss":4.6,"slug":"cve-2024-24857-linux-kernel-race-condition-in-bluetooth-device-driver","title":"Linux Kernel race condition in Bluetooth device driver","severity":"medium","exploited":false,"published_at":"2024-02-05T08:15:44.533+00:00","url":"https://junglewise.ai/threats/cve-2024-24857-linux-kernel-race-condition-in-bluetooth-device-driver"}],"generated_at":"2026-09-26T10:07:00.179841+00:00"}