Security1 publisher2 min readPublished
Siemens lists four SIMATIC AX Runtime Core Linux packages as affected by the Copy Fail flaw, with no fix available
CVE-2026-31431 gives Siemens HMI panel owners one target build, 21.0.2.1, across dozens of order numbers, while operators of the SIMATIC AX Runtime Core Linux packages are left with countermeasures until a fix ships.
The Watch · Security desk

What happened
- Siemens has tagged multiple SIPLUS and SIMATIC products as affected by CVE-2026-31431, the flaw it calls "Copy Fail", in an advisory carried by CISA.
- The SIMATIC HMI panels are enumerated one Siemens order number at a time across the MTP1000, MTP1200, MTP1500 and MTP1900 families, including the hygienic and neutral-design variants.
- Siemens says it has fixed several products already, is preparing further fix versions, and recommends specific countermeasures where a fix is not yet available.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Scope is decided by the order number stamped on the device, so a walk-down that records screen size and the words "Comfort Panel" will not tell an owner whether a given panel is in the advisory.
- exposure AX Runtime deployments, including the container and VMware development packages, stay exposed for as long as the further fix versions take, and Siemens' countermeasures are the only control it offers there.
- decision Owners have to choose compensating controls without knowing whether the flaw is reachable over the network or needs local access, because neither a vector nor a score is published.
The published summary does not say what Copy Fail does. The text CISA carried with the product list has no description of the flaw and no CVSS score [10]. Exploitability cannot be rated from it. The list itself is the operational content: one build number, and a long column of Siemens order numbers.
Count the entries in the text as supplied and there are 33 [7]. Twenty-eight are HMI panels [7]. Four are SIMATIC AX Runtime Core Linux packages [4]. One is the SIMATIC CN 4100, affected below version 6.0 [5]. All 28 panel entries resolve to the same fixed version, 21.0.2.1 [8].
Owners have to match order numbers. SIMATIC HMI MTP1000 Unified Basic is listed as 6AV2123-3KB32-0AW0 and the MTP1000 Unified Comfort Panel as 6AV2128-3KB06-0AX1, with the hygienic and neutral-design variants each carrying their own number [6]. Because every panel entry converges on one build, the question during a walk-down is whether the number on the back of the device appears in Siemens' list, not which version to stage.
Siemens records the four AX Runtime entries as vers:all/*, which is every version, and publishes no fixed build for them [4]. Two of the four are development artifacts by name: a Platform Container Common Debian Development package and a VMWare Development package [4]. Affected copies therefore sit in build and test environments as well as on runtime hosts. Siemens says it is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet, available [2].
One limit on the inventory: the affected-products list breaks off mid-entry after the MTP1900 Comfort Pro rows [9]. Twenty-eight panel order numbers is a floor. Anyone reconciling a fleet needs Siemens' full list.
For the products that are covered, the instruction is the ordinary one. Siemens has released new versions for several affected products and recommends updating to the latest versions [1].
What to watch
- Siemens' further fix versions for the four SIMATIC AX Runtime Core Linux packages, which the advisory says are in preparation.
- Any published mechanism or CVSS score for CVE-2026-31431; with either, AX Runtime owners could judge whether the flaw is reachable over the network.
- The remainder of the affected-products list beyond the MTP1900 Comfort Pro entries.