PatchSiren cyber security CVE debrief
CVE-2025-29999 Siemens CVE debrief
CVE-2025-29999 affects Siemens License Server (SLS). According to the advisory, the application searches for executable files in its application folder without proper validation. In a successful abuse scenario, an attacker who can place a malicious executable in that same directory may achieve arbitrary code execution with administrative privileges on the affected system. Siemens lists an update to V4.3 or later as the fix.
- Vendor
- Siemens
- Product
- Unknown
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-08
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-08
- Advisory updated
- 2025-05-06
Who should care
Organizations running Siemens License Server (SLS), especially administrators responsible for Windows hosts in operational technology or industrial environments. Also relevant to security teams enforcing least privilege and write-access controls on application directories.
Technical summary
The advisory describes a directory-validation weakness in Siemens License Server (SLS): the software searches for executables in its application folder without proper validation. If an attacker can place a malicious executable in that directory, the application may run it with administrative privileges. The CVSS vector provided by the source is AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H, indicating local access, low privileges, and user interaction are required, but the potential impact is high.
Defensive priority
Medium-to-high priority for affected deployments. The issue is rated CVSS 6.7 (Medium), but the potential outcome is administrative code execution on the SLS host, so upgrading should be prioritized.
Recommended defensive actions
- Update Siemens License Server (SLS) to V4.3 or later.
- Restrict write access to the application folder so only trusted administrators and service accounts can modify it.
- Review the SLS host for unexpected executables or recent file changes in the application directory.
- Limit local access and enforce least privilege on systems running SLS.
- Use application control or allowlisting where appropriate to reduce the risk of unintended executable launch.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-100-01 and Siemens advisory references for Siemens License Server (SLS). The source description states that improper validation of executable files in the application folder could allow arbitrary code execution with administrative privileges. The source revision history shows the 2025-05-06 update was a typo-fix revision, not a new disclosure date.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-29999 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-29999
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-29999 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-29999
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-525431.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-525431.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.