CVE-2023-28531
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...
Affects 4 products across 3 vendors.
Software does not restrict or incorrectly restricts access to a resource.
Show all 17
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2023-28531 affects OpenSSH versions before 9.3, where ssh-add adds smartcard keys to ssh-agent without the intended per-hop destination constraints. This can lead to unauthorized access and data exfiltration. The CVSS score is 9.8, indicating a critical severity. Affected vendors include Fujitsu-Siemens, Netapp, OpenBSD, and Siemens. No public PoC or exploits are known, and the EPSS score is low, suggesting a minimal likelihood of exploitation in the wild.
BSID: BS-2023-GLOBAL-060776-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-28531?
What is the CVSS score for CVE-2023-28531?
Is CVE-2023-28531 actively exploited?
How do I remediate CVE-2023-28531?
What systems are affected by CVE-2023-28531?
What NERC-CIP standard applies to CVE-2023-28531?
What IEC 62443 requirement maps to CVE-2023-28531?
| CVE ID | CVE-2023-28531 |
|---|---|
| BSID | BS-2023-GLOBAL-060776-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-07-28 |
| Last Modified | 2026-07-28 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by adding smartcard keys to the ssh-agent without the intended per-hop destination constraints, potentially allowing unauthorized access to remote systems and data exfiltration. The attack can be performed over the network with no user interaction required.
Exploitation Likelihood: MINIMAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Netapp | Solidfire Element Os | — |
| Netapp | Hci Bootstrap Os | — |
| Netapp | Brocade Fabric Operating System | — |
| Openbsd | Openssh | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access controls and monitor for unusual SSH activity. Ensure that only authorized users can add keys to the ssh-agent and that keys are properly constrained.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 by allowing unauthorized access to electronic security perimeters, which can compromise the security of critical assets.
This CVE maps to SR 7.6, which requires the implementation of access control measures to prevent unauthorized access to network resources. The vulnerability allows smartcard keys to be added without proper constraints, leading to potential unauthorized access.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 9a5144d37ace1a4de00cc2739f0e688eaf65ee69ee89d40120e76cff1b4fcbf1b82be2c1d3e9d1e13de96b09e646e48a363b91760432ce24fb6ed12e010983e2 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →