CVE-2026-31431
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...
Affects 49 products across 12 vendors.
The Linux kernel's crypto module, specifically the algif_aead component, contains a vulnerability that has been addressed by reverting to out-of-place operations. This change simplifies the code and removes unnecessary complexity, reducing the risk of potential security issues. The vulnerability is rated as high severity with a CVSS score of 7.8, and it affects multiple vendors and distributions. While there is no known exploit, a public proof of concept exists, and the vulnerability is listed in the KEV catalog.
BSID: BS-2026-GLOBAL-271236-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-31431?
What is the CVSS score for CVE-2026-31431?
Is CVE-2026-31431 actively exploited?
How do I remediate CVE-2026-31431?
What systems are affected by CVE-2026-31431?
What NERC-CIP standard applies to CVE-2026-31431?
What IEC 62443 requirement maps to CVE-2026-31431?
| CVE ID | CVE-2026-31431 |
|---|---|
| BSID | BS-2026-GLOBAL-271236-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-07-28 |
| Last Modified | 2026-07-28 |
| ICS Relevance | 85% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited locally by an attacker with low privileges. The attacker could potentially cause a denial of service, gain unauthorized access, or manipulate data. The attack does not require user interaction and can affect the confidentiality, integrity, and availability of the system.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Amazon | Amazon Linux | — |
| Arista | Velocloud Gateway | — |
| Arista | Cloudvision Portal | — |
| Arista | Cloudvision Agni | — |
| Arista | Velocloud Edge | — |
| Arista | Netvisor Os | — |
| Canonical | Ubuntu Linux | — |
| Debian | Debian Linux | — |
| Fortinet | — | — |
| Linux | Linux Kernel | — |
| Nixos | Nixos | — |
| Opensuse | Leap | — |
| Redhat | Enterprise Linux | — |
| Redhat | Openshift Container Platform | — |
| Siemens | Simatic S7-1500 Tm Mfp Firmware | — |
| Siemens | Simatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware | — |
| Siemens | Simatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp | — |
| Siemens | Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp Firmware | — |
| Siemens | Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp | — |
| Siemens | Siplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware | — |
| Siemens | Siplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp | — |
| Siemens | Simatic S7-1500 Tm Mfp | — |
| Siemens | Simatic S7-1500 Cpu 1518-4 Pn/Dp Mfp | — |
| Siemens | Simatic S7-1500 Cpu 1518-4 Pn/Dp Mfp Firmware | — |
| Siemens | Simatic S7-1500 Cpu 1518F-4 Pn/Dp Mfp | — |
| Siemens | Simatic S7-1500 Cpu 1518F-4 Pn/Dp Mfp Firmware | — |
| Siemens | Siplus S7-1500 Cpu 1518-4 Pn/Dp Mfp | — |
| Siemens | Siplus S7-1500 Cpu 1518-4 Pn/Dp Mfp Firmware | — |
| Suse | Caas Platform | — |
| Suse | Linux Enterprise Live Patching | — |
| Suse | Openstack Cloud | — |
| Suse | Linux Enterprise High Performance Computing | — |
| Suse | Manager Proxy | — |
| Suse | Manager Server | — |
| Suse | Linux Enterprise Workstation Extension | — |
| Suse | Linux Enterprise High Availability Extension | — |
| Suse | Linux Enterprise Real Time | — |
| Suse | Openstack Cloud Crowbar | — |
| Suse | Enterprise Storage | — |
| Suse | Manager Retail Branch Server | — |
| Suse | Linux Enterprise Micro | — |
| Suse | Basesystem Module | — |
| Suse | Development Tools Module | — |
| Suse | Legacy Module | — |
| Suse | Linux Micro | — |
| Suse | Public Cloud Module | — |
| Suse | Realtime Module | — |
| Suse | Linux Enterprise Server | — |
| Suse | Linux Enterprise Desktop | — |
| Vmware | Velocloud Orchestrator | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2026-05-01) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access controls and monitoring for the affected components to detect and prevent unauthorized access or manipulation.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE affects the integrity and availability of the system, which are critical for the secure operation of BES Cyber Systems. CIP-007-R2 requires the implementation of security controls to protect against unauthorized access and manipulation.
This CVE impacts the security of the system by potentially allowing unauthorized access and data manipulation. SR 7.6 requires the implementation of security measures to protect against such vulnerabilities and ensure the integrity and availability of the system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 25d5e54cb997dbfd1b9f59bb96286839325bd60c4497864ee8c72486839f24561be4fcf02ffde288f70248be8ca7088e77c9a23bb0942a896b24b11d71c7b71e |
This Vulnerability Is Being Actively Exploited
CVE-2026-31431 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →