CVE-2023-28531

CRITICAL

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...

Affects 4 products across 3 vendors.

BCS7.58
CVSS 3.19.8
EPSS2.3%
Percentile81th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2023-28531 affects OpenSSH versions before 9.3, where ssh-add adds smartcard keys to ssh-agent without the intended per-hop destination constraints. This can lead to unauthorized access and data exfiltration. The CVSS score is 9.8, indicating a critical severity. Affected vendors include Fujitsu-Siemens, Netapp, OpenBSD, and Siemens. No public PoC or exploits are known, and the EPSS score is low, suggesting a minimal likelihood of exploitation in the wild.

BSID: BS-2023-GLOBAL-060776-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-28531?
CVE-2023-28531 affects OpenSSH versions before 9.3, where ssh-add adds smartcard keys to ssh-agent without the intended per-hop destination constraints. This can lead to unauthorized access and data exfiltration. The CVSS score is 9.8, indicating a critical severity. Affected vendors include Fujitsu-Siemens, Netapp, OpenBSD, and Siemens. No public PoC or exploits are known, and the EPSS score is low, suggesting a minimal likelihood of exploitation in the wild.
What is the CVSS score for CVE-2023-28531?
CVE-2023-28531 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.3%.
Is CVE-2023-28531 actively exploited?
No confirmed active exploitation of CVE-2023-28531 as of 2026-07-29.
How do I remediate CVE-2023-28531?
Priority: MEDIUM.
What systems are affected by CVE-2023-28531?
CVE-2023-28531 affects: Netapp, Netapp, Netapp, Openbsd, Siemens.
What NERC-CIP standard applies to CVE-2023-28531?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 by allowing unauthorized access to electronic security perimeters, which can compromise the security of critical assets.
What IEC 62443 requirement maps to CVE-2023-28531?
IEC 62443 SR 7.6: This CVE maps to SR 7.6, which requires the implementation of access control measures to prevent unauthorized access to network resources. The vulnerability allows smartcard keys to be added without proper constraints, leading to potential unauthorized access.
Vulnerability Details
CVE IDCVE-2023-28531
BSIDBS-2023-GLOBAL-060776-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-07-28
Last Modified2026-07-28
ICS Relevance70%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by adding smartcard keys to the ssh-agent without the intended per-hop destination constraints, potentially allowing unauthorized access to remote systems and data exfiltration. The attack can be performed over the network with no user interaction required.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Netapp Solidfire Element Os
Netapp Hci Bootstrap Os
Netapp Brocade Fabric Operating System
Openbsd Openssh
Siemens —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict access controls and monitor for unusual SSH activity. Ensure that only authorized users can add keys to the ssh-agent and that keys are properly constrained.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 by allowing unauthorized access to electronic security perimeters, which can compromise the security of critical assets.
IEC 62443: SR 7.6
This CVE maps to SR 7.6, which requires the implementation of access control measures to prevent unauthorized access to network resources. The vulnerability allows smartcard keys to be added without proper constraints, leading to potential unauthorized access.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash9a5144d37ace1a4de00cc2739f0e688eaf65ee69ee89d40120e76cff1b4fcbf1b82be2c1d3e9d1e13de96b09e646e48a363b91760432ce24fb6ed12e010983e2
Related CVEs affecting Netapp
CVE-2008-3349 10.0 Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp ... CVE-2014-9353 10.0 NetApp OnCommand Balance before 4.2P2 contains a "default privileged account,... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2015-3292 10.0 The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x ... CVE-2020-4561 10.0 IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control r...
View all Netapp CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →