← All Advisories

CVE-2026-52998

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-52998

Key Details

CVECVE-2026-52998
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-476 (NULL Pointer Dereference)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check

The nf_osf_ttl() function accessed skb->dev to perform a local interface

address lookup without verifying that the device pointer was valid.

Additionally, the implementation utilized an in_dev_for_each_ifa_rcu

loop to match the packet source address against local interface

addresses. It assumed that packets from the same subnet should not see a

decrement on the initial TTL. A packet might appear it is from the same

subnet but it actually isn't especially in modern environments with

containers and virtual switching.

Remove the device dereference and interface loop. Replace the logic with

a switch statement that evaluates the TTL according to the ttl_check. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-52998
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-52998