PatchSiren cyber security CVE debrief
CVE-2023-52927 Siemens CVE debrief
CVE-2023-52927 is published in Siemens’ SIMATIC S7-1500 CPU family advisory and is assessed at medium severity with an availability-only impact profile. The advisory says no fix is currently available for the listed CPU variants. Siemens recommends limiting access to the additional GNU/Linux subsystem to trusted personnel and only building or running applications from trusted sources.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators, engineers, and maintainers responsible for the listed Siemens SIMATIC S7-1500 CPU variants, especially environments that use the additional GNU/Linux subsystem or run custom applications on those devices.
Technical summary
The CVE description states that nf_conntrack_in() calling nf_ct_find_expectation() can remove an expectation entry from the hash table, while some scenarios require the expectation to remain until a created connection is confirmed. The patch changes the template status so the expectation is not removed in those scenarios. In the Siemens CSAF advisory, the issue is mapped to five SIMATIC S7-1500 CPU product identifiers and scored with CVSS 3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local, hard-to-exploit condition with high availability impact and no confidentiality or integrity impact in the advisory’s scoring.
Defensive priority
Medium. The advisory indicates no fix is available, so exposure reduction and operational controls are the primary defenses for affected deployments.
Recommended defensive actions
- Restrict access to the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on affected devices.
- Review whether any affected Siemens CPU variants are deployed in your environment and inventory them by product identifier.
- Monitor Siemens and CISA advisory updates for any future remediation guidance or revised mitigation advice.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-162-05 and the linked Siemens ProductCERT advisory SSA-082556. The source advisory lists five affected SIMATIC S7-1500 CPU product names, states that no fix is currently available, and provides mitigation guidance focused on restricting subsystem access and trusting application sources. The published date used here is the advisory publication date: 2025-06-10, with later republication updates reflected in the source timeline.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-52927 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-52927
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-52927 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52927
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.