CISA

Siemens SIPLUS and SIMATIC Products

From Cybersecurity and Infrastructure Security Agency ↗

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

The following versions of Siemens SIPLUS and SIMATIC Products are affected:

SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431)

SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431)

SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431)

SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431)

SIMATIC CN 4100 vers:intdot/