← All Advisories

CVE-2026-43057

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-43057

Key Details

CVECVE-2026-43057
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback

NETIF_F_IPV6_CSUM only advertises support for checksum offload of

packets without IPv6 extension headers. Packets with extension

headers must fall back onto software checksumming. Since TSO

depends on checksum offload, those must revert to GSO.

The below commit introduces that fallback. It always checks

network header length. For tunneled packets, the inner header length

must be checked instead. Extend the check accordingly.

A special case is tunneled packets without inner IP protocol. Such as

RFC 6951 SCTP in UDP. Those are not standard IPv6 followed by

transport header either, so also must revert to the software GSO path. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-43057
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-43057