Home/Blog/News

Siemens Confirms 40+ SIMATIC/SIPLUS Products Vulnerable to Actively Exploited "Copy Fail" Kernel Flaw

CISA advisory ICSA-26-265-04 ties Siemens SIMATIC AX Runtime, CN 4100, IoT2050, and HMI MTP hardware to CVE-2026-31431 — a Linux kernel privilege-escalation bug already on CISA's Known Exploited Vulnerabilities catalog.

OT SecuritySeptember 25, 2026Smart Machines & Factories

On September 22, 2026, CISA published advisory ICSA-26-265-04, confirming that more than 40 Siemens SIMATIC and SIPLUS product variants are affected by CVE-2026-31431 — the Linux kernel vulnerability nicknamed "Copy Fail." The flaw carries a CVSS score of 7.8 (High) and has been on CISA's Known Exploited Vulnerabilities (KEV) catalog since May 1, 2026, meaning active exploitation was already underway before Siemens' own product line was formally tied to it.

What "Copy Fail" Actually Does

CVE-2026-31431 lives in the Linux kernel's cryptographic subsystem, specifically the algif_aead component. CISA classifies it as "Incorrect Resource Transfer Between Spheres": the flaw triggers when the kernel operates in-place on a memory buffer instead of using separate source and destination mappings during a crypto copy operation. A locally authenticated user, or a compromised container workload with local access, can exploit the miscalculation to escalate privileges and obtain a root shell — full control of the underlying Linux host.

The vulnerability was originally disclosed by security firm Theori in April 2026 and patched upstream in Linux kernel versions 6.18.22, 6.19.12, and 7.0. What changed on September 22 is that Siemens' ProductCERT confirmed the flaw reaches deep into its industrial product line — devices that run a Linux subsystem underneath their real-time control firmware.

Affected Siemens Products (partial list, all versions below the fixed release)

  • SIMATIC AX Runtime (Linux-based versions) — below V21 Update 2 SR1;
  • SIMATIC CN 4100 communication node — below version 6.0;
  • SIMATIC IoT2050 Advanced edge gateway;
  • SIMATIC and SIPLUS HMI MTP series (1000, 1200, 1500, 1900, 2200, 400, 700) — over 40 product variants in total.

Why a Local-Privilege Bug Matters on the Plant Floor

CVE-2026-31431 requires local access to exploit, which on an office laptop sounds like a lower-priority bug. On a SIMATIC AX Runtime controller or an IoT2050 edge gateway, "local access" has a different meaning: it's whatever an attacker already reached through a separate foothold — a compromised HMI session, a container deployed via CI/CD to the edge device, an exposed engineering interface, or a supply-chain-tainted application package. Once that foothold exists, Copy Fail is the step that turns limited access into root on the Linux layer underneath the control logic — the layer that can touch device configuration, network stack, and in some architectures the boundary with the real-time control firmware itself.

CISA's advisory lists six affected critical-infrastructure sectors for the Siemens product set: Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities — the same sectors that have shown up repeatedly in ICS Patch Tuesday advisories this year for Schneider Electric and AVEVA products.

Patch and Mitigation Path

Siemens has released fixed firmware for the affected lines:

  1. SIMATIC AX Runtime and HMI MTP products — update to V21 Update 2 SR1 or later.
  2. SIMATIC CN 4100 — update to version 6.0 or later.
  3. Where an immediate update isn't possible: restrict interactive shell access on the Linux subsystem to authorized personnel only, and only deploy applications and containers from trusted, verified sources — Siemens' stated interim mitigation in the absence of a patch window.

Because CVE-2026-31431 is already in the KEV catalog, U.S. federal agencies operating affected equipment are under a binding operational directive remediation deadline; private-sector operators in the listed sectors should treat the same timeline as a practical minimum rather than a regulatory technicality — exploitation in the wild predates this advisory by nearly five months.

Tracking which edge gateways, HMIs, and runtime controllers in a fleet are running which firmware version — and getting patch status into a dashboard someone actually checks — is an integration problem as much as a security one. YuSMP Group builds asset-inventory and OT monitoring integrations that connect plant-floor device fleets to centralized patch-management and alerting systems.

Sources: CISA ICS Advisory ICSA-26-265-04; Siemens ProductCERT.

← Back to Blog Smart Machines & Factories