PatchSiren cyber security CVE debrief
CVE-2025-21762 Siemens CVE debrief
CVE-2025-21762 is a Linux kernel availability vulnerability that Siemens mapped to SIMATIC S7-1500 TM MFP - BIOS in its industrial advisory. The kernel issue is described as a missing RCU-protection problem in arp_xmit(), which could create a potential use-after-free condition when the function is called without RTNL or RCU protection. For defenders, the main concern is service disruption rather than data exposure: the supplied CVSS vector shows local access, low privileges, no user interaction, and high availability impact only. Siemens’ advisory notes that no fix was available at publication time and advises only using trusted sources for building and running applications while following industrial cybersecurity best practices.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - BIOS
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-27
- Original CVE updated
- 2026-07-30
- Advisory published
- 2025-02-27
- Advisory updated
- 2026-07-30
Who should care
Siemens SIMATIC S7-1500 TM MFP operators, OT/ICS engineers, system administrators, and security teams responsible for Linux-based industrial platforms that include the affected Siemens product.
Technical summary
The advisory states that arp_xmit() can be invoked without RTNL or RCU protection. The resolution is to add RCU protection to avoid a potential use-after-free. Based on the supplied CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), the practical risk is local exploitation leading to availability impact.
Defensive priority
Medium
Recommended defensive actions
- Track Siemens advisory SSA-503939 and the CISA ICS advisory for updates, since the supplied source says no fix was available at publication time.
- Apply Siemens guidance to only build and run applications from trusted sources.
- Follow CISA ICS recommended practices and defense-in-depth guidance for industrial control systems.
- Review whether the affected Siemens SIMATIC S7-1500 TM MFP - BIOS product is deployed in your environment and document compensating controls until a vendor fix is available.
- Limit local access and privileged use on affected systems to reduce exposure to the local/low-privilege attack conditions indicated by the CVSS vector.
Evidence notes
The source corpus links CVE-2025-21762 to CISA advisory ICSA-25-072-03 and Siemens advisory SSA-503939. The advisory description explicitly says the Linux kernel vulnerability is resolved by using RCU protection in arp_xmit() to avoid a potential UAF. The remediations section states that no fix was available at publication time and provides a trusted-sources-only workaround. The supplied CVSS vector indicates local, low-privilege, no-interaction conditions with availability impact only.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21762 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21762
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21762 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21762
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-503939.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-503939.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.