PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21806 Siemens CVE debrief

CVE-2025-21806 is a Siemens advisory for the SIMATIC S7-1500 TM MFP - BIOS. The issue is described as a networking-stability problem involving a NULL net_device condition, with impact limited to availability. The CVSS vector provided by the advisory indicates a local attack path with low privileges and high availability impact, but no confidentiality or integrity impact. As of the advisory’s latest revision, Siemens lists no fix available.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - BIOS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

OT and industrial control system administrators responsible for Siemens SIMATIC S7-1500 TM MFP deployments, especially teams managing BIOS/firmware lifecycle, trusted application sourcing, and operational availability monitoring.

Technical summary

The source advisory describes a kernel-networking stability defect: "net: let net.core.dev_weight always be non-zero" and notes the issue was encountered during stability testing with a "(NULL net_device)" condition. The supplied CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local, low-privilege denial-of-service style availability impact. The advisory does not provide exploitation details or a confirmed remote attack path, and it states that no fix is currently available.

Defensive priority

Medium. The issue is publicly disclosed and affects availability, but the source material does not indicate remote exploitation, KEV inclusion, or known ransomware use. Prioritize if the affected Siemens platform is operationally critical or if local user access is difficult to control.

Recommended defensive actions

  • Identify whether any SIMATIC S7-1500 TM MFP - BIOS deployments are in use in your environment.
  • Treat the affected device as an availability-sensitive asset and review local-access controls, trusted software sourcing, and maintenance procedures.
  • Monitor Siemens and CISA advisories for a vendor fix or updated mitigation guidance.
  • Apply ICS defense-in-depth practices from CISA, including least privilege, segmentation, and strict control of trusted applications.
  • Validate operational backups, recovery procedures, and outage response plans for impacted systems.

Evidence notes

This debrief is based only on the supplied CISA CSAF advisory data and the linked official Siemens/CISA references. The advisory was published on 2025-03-11 and last modified on 2025-09-09. The source explicitly states "Currently no fix is available" and recommends, as a workaround, "Only build and run applications from trusted sources." No KEV listing or ransomware-campaign note was provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21806 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21806

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21806 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21806

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-503939.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-503939.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.