← All Advisories

CVE-2026-31414

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31414

Key Details

CVECVE-2026-31414
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_expect: use expect->helper

Use expect->helper in ctnetlink and /proc to dump the helper name.

Using nfct_help() without holding a reference to the master conntrack

is unsafe.

Use exp->master->helper in ctnetlink path if userspace does not provide

an explicit helper when creating an expectation to retain the existing

behaviour. The ctnetlink expectation path holds the reference on the

master conntrack and nf_conntrack_expect lock and the nfnetlink glue

path refers to the master ct that is attached to the skb. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31414
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31414