PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15284 Siemens CVE debrief

CVE-2025-15284 is a denial-of-service issue published by CISA on 2026-03-10 and republished on 2026-03-12 in Siemens advisory content. The source corpus says the underlying problem is improper input validation in qs parsing: bracket notation can bypass arrayLimit enforcement, allowing unbounded array growth and memory exhaustion.

Vendor
Siemens
Product
SIDIS Prime
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-12
Advisory published
2026-03-10
Advisory updated
2026-03-12

Who should care

Siemens SIDIS Prime operators covered by the advisory, and any teams running applications that parse untrusted query strings with qs.parse() and rely on arrayLimit to constrain resource use.

Technical summary

The supplied advisory text states that qs versions below 6.14.1 are affected. The flaw is in parse handling for bracket notation such as a[]=1&a[]=2: the source describes a code path that combines values without checking options.arrayLimit, while indexed notation a[0]=1&a[1]=2 does enforce the limit. As a result, an attacker can send many bracket-notation parameters and force large in-memory arrays, creating a network-reachable HTTP denial of service. The source corpus assigns CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and scores it 7.5 HIGH.

Defensive priority

High. This is unauthenticated, network-reachable availability impact with a plausible single-request memory-exhaustion path.

Recommended defensive actions

  • Apply the vendor remediation listed in the advisory: update Siemens SIDIS Prime to V4.0.800 or later.
  • If your application uses qs directly, confirm the deployed qs version is 6.14.1 or later.
  • Review any code that parses attacker-controlled query strings and does not assume arrayLimit alone is sufficient for protection.
  • Add request-size, parameter-count, and upstream rate-limiting controls to reduce DoS exposure.
  • Monitor service memory and crash/restart telemetry for abnormal spikes while patching is rolled out.

Evidence notes

The source corpus contains a notable context mismatch: the advisory metadata is for Siemens SIDIS Prime, but the technical description is about qs parse behavior and the arrayLimit bypass. The description is also truncated in the supplied notes. All claims in this debrief are limited to the provided CISA/Siemens-linked corpus and official reference links.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15284 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15284

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15284 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15284

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.