PatchSiren cyber security CVE debrief
CVE-2025-0836 Siemens CVE debrief
CVE-2025-0836 is a medium-severity authorization flaw published on 2026-02-10 and republished by CISA on 2026-02-12. The advisory says users with read-only access to the Management Server may gain full read/write access to the MIP Webhooks API, so organizations should treat Management Server role settings as security-sensitive until patched.
- Vendor
- Siemens
- Product
- Siveillance Video V2022 R3
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-12
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-12
Who should care
Administrators and security teams responsible for Siemens Siveillance Video Management Servers, especially environments running the affected releases listed in the advisory. OT/physical-security operations teams should also review access controls for management-plane accounts that have read-only roles but may be able to modify webhook configuration.
Technical summary
The source advisory describes a missing authorization issue (CWE-862) with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L (6.3, Medium). In practical terms, an authenticated user with read-only access to the Management Server can be able to interact with the MIP Webhooks API as if they had read/write access. The advisory lists vendor fixes for Siveillance Video V2022 R3, V2023 R1, V2023 R2, V2023 R3, V2024 R1, and V2025, and recommends auditing role security settings if patching is not immediately possible.
Defensive priority
Prioritize patching before relying on compensating controls, because the issue affects management-plane authorization and can turn read-only access into write capability. If immediate patching is not possible, review every read-only Management Server role and assume those users may have effective write access to Webhooks configuration until proven otherwise.
Recommended defensive actions
- Update to the vendor-fixed release for your product line: V23.1 HotfixRev18, V23.2 HotfixRev18, V23.3 HotfixRev23, V24.1 HotfixRev14, or V25.1 HotfixRev8, as applicable.
- Audit Management Server role assignments and verify that read-only users cannot modify MIP Webhooks configuration.
- Restrict access to management interfaces to trusted administrative networks and accounts only.
- Review webhook-related configuration and logs for unexpected changes or access by accounts that should be read-only.
- If patching is delayed, treat read-only access to the Management Server as effectively privileged for Webhooks configuration until remediation is complete.
Evidence notes
Primary evidence comes from the CISA CSAF republication of Siemens ProductCERT advisory SSA-625934 (ICSA-26-043-07), which states the missing authorization condition and the remediation guidance. The source corpus also lists the CVSS vector 3.1 score of 6.3 and the affected Siveillance Video product versions. Note: the advisory description mentions Milestone Systems XProtect VMS and MIP Webhooks API, while the CSAF product tree and remediation entries are for Siemens Siveillance Video; this wording inconsistency is present in the supplied source corpus and is not resolved here. No exploit code or weaponized reproduction details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0836 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0836
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0836 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0836
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625934.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-625934.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.