PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-27587 Siemens CVE debrief

Siemens’ advisory, republished by CISA as ICSA-26-043-06, ties CVE-2025-27587 to OpenSSL 3.0.0 through 3.3.2 on PowerPC-based systems used in Siemens OT products including RUGGEDCOM RST2428P and the SCALANCE family. The source describes a Minerva-style timing side-channel during EVP_DigestSign operations that could, under the conditions described, help an attacker infer nonce-related information and potentially recover a private key. Siemens’ remediation guidance is to update to version 3.3 or later where supported. The advisory also notes that the CVE is disputed because the timing signal is extremely small and is described as requiring an attacker process on the same physical system, which OpenSSL considers outside its threat model.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-28
Original CVE updated
2026-02-25
Advisory published
2026-01-28
Advisory updated
2026-02-25

Who should care

OT operators, security teams, and maintenance owners responsible for Siemens RUGGEDCOM RST2428P, SCALANCE devices, or any PowerPC-based embedded systems running OpenSSL 3.0.0 through 3.3.2. This is most relevant where local execution or same-host co-residency is plausible.

Technical summary

The supplied description says the issue is a timing side-channel in OpenSSL on PowerPC architecture. It involves measuring signing time for random messages through EVP_DigestSign, then using statistical comparison of signatures associated with different nonce sizes to infer information about the private key. The source also states the signal is very small and, per the dispute note, is not feasible to detect without an attacker process on the same physical system.

Defensive priority

Medium; remediate on affected Siemens firmware during the next planned maintenance window, with higher urgency if the deployment uses PowerPC and locally reachable execution contexts.

Recommended defensive actions

  • Inventory Siemens RUGGEDCOM and SCALANCE assets to confirm whether any affected firmware embeds OpenSSL 3.0.0 through 3.3.2 on PowerPC.
  • Apply Siemens’ recommended update to version 3.3 or later where supported.
  • Validate the exact firmware and OpenSSL build in use before scheduling downtime, since the advisory scope is product- and architecture-specific.
  • Reduce opportunities for same-system co-residency and local code execution on affected hosts where possible.
  • Track Siemens ProductCERT SSA-089022 and CISA ICSA-26-043-06 for revisions or product-scope clarifications.
  • Document residual risk if a device cannot be upgraded immediately and the timing side-channel is judged infeasible in your environment.

Evidence notes

This debrief is based on the supplied CISA CSAF source item for ICSA-26-043-06, which republishes Siemens ProductCERT SSA-089022. The source metadata lists Siemens RUGGEDCOM RST2428P and multiple SCALANCE products, and the remediation section says to update to V3.3 or later for affected products. The description explicitly says the CVE is disputed and that detection would require an attacker process on the same physical system. Timing context uses the supplied advisory publish date of 2026-01-28 and update date of 2026-02-25.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-27587 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-27587

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-27587 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27587

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.