PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-24956 Siemens CVE debrief

CVE-2025-24956 affects Siemens OpenV2G and stems from a missing length check while parsing X509 serial numbers in EXI data. Siemens and CISA describe the issue as a buffer overflow that can lead to memory corruption; the provided CVSS vector rates it medium severity, with high availability impact. A vendor fix is available in OpenV2G 0.9.6 or later.

Vendor
Siemens
Product
OpenV2G
CVSS
MEDIUM 6.2
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-11
Original CVE updated
2025-05-06
Advisory published
2025-02-11
Advisory updated
2025-05-06

Who should care

Organizations that deploy or integrate Siemens OpenV2G, especially teams responsible for EV charging, industrial, or embedded environments that process EXI input. Security and operations teams should care if OpenV2G is present in products, test systems, or any workflow that accepts untrusted serialized certificate data.

Technical summary

The advisory states that OpenV2G’s EXI parsing feature is missing a length check when handling X509 serial numbers. That parsing flaw can allow a buffer overflow and resulting memory corruption. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which indicates a local, low-complexity attack path with primary availability impact. Siemens recommends updating to OpenV2G 0.9.6 or later.

Defensive priority

Prioritize remediation for any affected deployment because the flaw can cause memory corruption and the vendor provides a fixed release. Although the CVSS score is medium, the combination of low attack complexity and high availability impact makes this worth prompt operational attention in any system that processes EXI input.

Recommended defensive actions

  • Update Siemens OpenV2G to version 0.9.6 or later as the vendor remediation.
  • Inventory systems and products that include OpenV2G to confirm whether they are affected.
  • Where possible, minimize exposure of affected parsing paths and treat untrusted EXI input cautiously until patched.
  • Monitor affected systems for unexpected crashes, memory faults, or process restarts that could indicate parser instability.
  • Follow CISA industrial control system defensive guidance and defense-in-depth practices for the surrounding environment.

Evidence notes

The source corpus is CISA advisory ICSA-25-044-08 for Siemens OpenV2G, published on 2025-02-11 and revised on 2025-05-06 for typo fixes only. The advisory text states that the EXI parsing feature is missing a length check when parsing X509 serial numbers, which can lead to a buffer overflow and memory corruption. The remediation listed in the supplied material is to update to OpenV2G 0.9.6 or later. No KEV entry is provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-24956 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-24956

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-24956 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24956

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-647005.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-647005.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.