← All Advisories

CVE-2026-46033

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-46033

Key Details

CVECVE-2026-46033
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

crypto: authencesn - reject short ahash digests during instance creation

authencesn requires either a zero authsize or an authsize of at least

4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of

high-order sequence number data at the end of the authenticated data.

While crypto_authenc_esn_setauthsize() already rejects explicit

non-zero authsizes in the range 1..3, crypto_authenc_esn_create()

still copied auth->digestsize into inst->alg.maxauthsize without

validating it. The AEAD core then initialized the tfm's default

authsize from that value.

As a result, selecting an ahash with digest size 1..3, such as

cbcmac(cipher_null), exposed authencesn instances whose default

authsize was invalid even though setauthsize() would have rejected the

same value. AF_ALG could then trigger the ESN tail handling with a

too-short tag and hit an out-of-bounds access.

Reject authencesn instances whose ahash digest size is in the invalid

non-zero range 1..3 so that no tfm can inherit an unsupported default

authsize. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-46033
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-46033