PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-27769 Siemens CVE debrief

CVE-2025-27769 affects Siemens Heliox EV charging stations and is rated LOW with a 2.6 CVSS score. The issue is an improper access control weakness that could let an attacker reach unauthorized services through the charging cable.

Vendor
Siemens
Product
Heliox Flex 180 kW EV Charging Station
CVSS
LOW 2.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-12
Advisory published
2026-03-10
Advisory updated
2026-03-12

Who should care

Operators, maintainers, and integrators responsible for Siemens Heliox Flex 180 kW EV Charging Station systems below F4.11.1 and Heliox Mobile DC 40 kW EV Charging Station systems below L4.10.1 should review this advisory. Site security teams and EV charging service providers should also prioritize it where physical access to charging equipment is possible.

Technical summary

The advisory describes an improper access control condition in affected Siemens Heliox EV charging stations. According to the supplied CVSS vector (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N), exploitation requires physical access, has low attack complexity, and can impact confidentiality at a limited level while not indicating integrity or availability impact in the base score. The reported attack path is via the charging cable, which suggests an unauthorized local interface or service exposure rather than a network-only weakness.

Defensive priority

Low to moderate. The issue is physically reachable and limited in measured impact, but it affects safety- and availability-relevant charging infrastructure and should still be remediated promptly at sites with public or semi-public access.

Recommended defensive actions

  • Contact Siemens customer support for patch information and apply the OTA update guidance provided in the advisory.
  • Inventory deployed Heliox Flex 180 kW EV Charging Station and Heliox Mobile DC 40 kW EV Charging Station assets and compare installed versions against the affected thresholds.
  • Restrict physical access to charging equipment and cable interfaces where feasible, especially at unattended sites.
  • Monitor Siemens/CISA advisory updates for any follow-on guidance or revised remediation details.
  • Validate that local operational controls and maintenance procedures limit unauthorized use of charging infrastructure.

Evidence notes

This debrief is based on the supplied CISA CSAF source item for ICSA-26-071-05 and its Siemens ProductCERT reference set. The source description states: 'Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.' The source metadata lists the affected products and version constraints, the remediation note directs customers to contact support for patch information via OTA update, and the CVSS vector is provided as CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. Publication timing is taken from the supplied CVE and advisory dates: 2026-03-10 initial publication and 2026-03-12 republication/revision.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-27769 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-27769

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-27769 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27769

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-126399.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-126399.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.