← All Advisories

CVE-2026-31682

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31682

Key Details

CVECVE-2026-31682
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bridge: br_nd_send: linearize skb before parsing ND options

br_nd_send() parses neighbour discovery options from ns->opt[] and

assumes that these options are in the linear part of request.

Its callers only guarantee that the ICMPv6 header and target address

are available, so the option area can still be non-linear. Parsing

ns->opt[] in that case can access data past the linear buffer.

Linearize request before option parsing and derive ns from the linear

network header. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31682
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31682