PatchSiren cyber security CVE debrief
CVE-2025-15284 Siemens CVE debrief
CVE-2025-15284 is a denial-of-service issue published by CISA on 2026-03-10 and republished on 2026-03-12 in Siemens advisory content. The source corpus says the underlying problem is improper input validation in qs parsing: bracket notation can bypass arrayLimit enforcement, allowing unbounded array growth and memory exhaustion.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-03-12
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-03-12
Who should care
Siemens SIDIS Prime operators covered by the advisory, and any teams running applications that parse untrusted query strings with qs.parse() and rely on arrayLimit to constrain resource use.
Technical summary
The supplied advisory text states that qs versions below 6.14.1 are affected. The flaw is in parse handling for bracket notation such as a[]=1&a[]=2: the source describes a code path that combines values without checking options.arrayLimit, while indexed notation a[0]=1&a[1]=2 does enforce the limit. As a result, an attacker can send many bracket-notation parameters and force large in-memory arrays, creating a network-reachable HTTP denial of service. The source corpus assigns CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and scores it 7.5 HIGH.
Defensive priority
High. This is unauthenticated, network-reachable availability impact with a plausible single-request memory-exhaustion path.
Recommended defensive actions
- Apply the vendor remediation listed in the advisory: update Siemens SIDIS Prime to V4.0.800 or later.
- If your application uses qs directly, confirm the deployed qs version is 6.14.1 or later.
- Review any code that parses attacker-controlled query strings and does not assume arrayLimit alone is sufficient for protection.
- Add request-size, parameter-count, and upstream rate-limiting controls to reduce DoS exposure.
- Monitor service memory and crash/restart telemetry for abnormal spikes while patching is rolled out.
Evidence notes
The source corpus contains a notable context mismatch: the advisory metadata is for Siemens SIDIS Prime, but the technical description is about qs parse behavior and the arrayLimit bypass. The description is also truncated in the supplied notes. All claims in this debrief are limited to the provided CISA/Siemens-linked corpus and official reference links.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15284 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15284
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15284 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15284
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.