PatchSiren cyber security CVE debrief
CVE-2025-21776 Siemens CVE debrief
CVE-2025-21776 is a publicly disclosed availability issue that the CISA/Siemens advisory maps to Siemens SIMATIC S7-1500 TM MFP - BIOS. The advisory says a test program can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer, and it lists no fix at publication time. Because the CVSS vector requires local access and high privileges, the main concern is targeted disruption on affected systems rather than remote compromise.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - BIOS
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Siemens SIMATIC S7-1500 TM MFP - BIOS owners and operators, OT/ICS administrators, and security teams that allow local application or test-program execution on these systems should pay attention. Environments that rely on tightly controlled software provenance should treat the vendor workaround as immediately relevant.
Technical summary
The supplied advisory text describes a USB hub handling flaw in which a test program can trigger usb_hub_to_struct_hub() to dereference a NULL or otherwise inappropriate pointer when presented with non-compliant devices that have too many configurations or interfaces. The stated CVSS vector is CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, indicating local access, high privileges, no user interaction, and availability-only impact. The remediation section in the source says there is currently no fix available and recommends only building and running applications from trusted sources.
Defensive priority
Medium priority: no fix was available in the source advisory, but exploitation requires local high privileges and the reported impact is availability-focused.
Recommended defensive actions
- Restrict local administrative access on affected Siemens systems and limit who can run applications or test programs.
- Follow the vendor workaround: only build and run applications from trusted sources.
- Monitor the Siemens and CISA advisory pages for a future fix or updated guidance.
- Apply CISA industrial-control-system defense-in-depth and recommended-practices guidance to reduce the impact of local faults and untrusted software.
- Review software provenance and change-control processes for any applications deployed to the affected product line.
Evidence notes
The source corpus is a CISA CSAF advisory (ICSA-25-072-03) published on 2025-03-11 and modified on 2025-09-09. It maps CVE-2025-21776 to Siemens SIMATIC S7-1500 TM MFP - BIOS, states that a test program can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer, and lists the remediation as "Currently no fix is available" with the workaround "Only build and run applications from trusted sources." The supplied CVSS vector is AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21776 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21776
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21776 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21776
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-503939.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-503939.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.