PatchSiren cyber security CVE debrief
CVE-2023-2975 Siemens CVE debrief
CVE-2023-2975 describes a cryptographic integrity issue in the AES-SIV path used by Siemens SIDIS Prime: empty associated data entries can be ignored, so those entries are not authenticated. The advisory says non-empty associated data is not affected, and it rates the issue as low severity because the condition is expected to be uncommon and no affected applications were known at publication time.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-11-14
- Original CVE updated
- 2023-11-14
- Advisory published
- 2023-11-14
- Advisory updated
- 2023-11-14
Who should care
Siemens SIDIS Prime operators, maintainers, and integrators that rely on AES-SIV for authenticated encryption, especially if their application may pass empty associated-data entries or depends on those entries remaining in the authenticated context.
Technical summary
According to the advisory, the affected AES-SIV implementation returns success when EVP_EncryptUpdate() or EVP_CipherUpdate() is called with a NULL output buffer and a zero input length for an empty associated-data entry. As a result, the empty entry is not authenticated. The issue does not affect authentication of non-empty associated data.
Defensive priority
Low to Medium
Recommended defensive actions
- Update Siemens SIDIS Prime to V4.0.700 or later, as listed in the vendor remediation guidance.
- Review application use of AES-SIV and confirm whether empty associated-data entries are possible or required.
- Add regression tests that verify empty associated data is authenticated as intended in your integration.
- If you cannot update immediately, inventory deployments that use the affected cryptographic path and assess whether the empty-entry case is relevant to your environment.
- Follow the Siemens and CISA advisory links for product-specific guidance and deployment validation steps.
Evidence notes
This debrief is based on the Siemens/CISA CSAF advisory and related official records for CVE-2023-2975. The source text states that empty associated data entries are ignored by the AES-SIV implementation, that non-empty associated data is unaffected, and that the issue is expected to be rare. The advisory provides a vendor fix version of V4.0.700 or later. No CISA KEV entry is present in the supplied data. The advisory was published on 2025-04-08 and revised on 2025-05-06 for typo fixes.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-2975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-2975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-2975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-2975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-277137.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-277137.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.