PatchSiren cyber security CVE debrief
CVE-2025-31929 Siemens CVE debrief
CVE-2025-31929 affects multiple Siemens VersiCharge AC Series EV charger models. According to the CISA CSAF advisory and Siemens product advisory, the affected devices do not contain an immutable root of trust in M0 hardware. A physical attacker could use that weakness to execute arbitrary code. Siemens lists no fix planned for the affected products.
- Vendor
- Siemens
- Product
- IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0)
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-13
- Original CVE updated
- 2025-05-13
- Advisory published
- 2025-05-13
- Advisory updated
- 2025-05-13
Who should care
Operators, owners, and maintainers of the affected Siemens VersiCharge AC Series EV chargers should care, especially sites where devices are physically accessible to unauthorized persons or where tampering risk is elevated.
Technical summary
The issue is a hardware trust-anchor weakness: the affected devices lack an immutable root of trust in M0 hardware. The advisory states that an attacker with physical access could leverage this condition to execute arbitrary code. The published CVSS vector is AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N, which aligns with a physical, high-complexity attack that primarily impacts integrity.
Defensive priority
Medium. The attack requires physical access, but the consequence can include arbitrary code execution and Siemens indicates no fix is planned. Prioritize for environments where chargers are exposed, unattended, or difficult to physically secure.
Recommended defensive actions
- Confirm whether any Siemens charger models in your fleet match the 38 affected product variants listed in the advisory.
- Restrict and monitor physical access to charging equipment and related service ports or enclosures.
- Apply defense-in-depth controls recommended for ICS/OT assets, including asset inventory, access control, logging, and tamper detection where available.
- Review Siemens and CISA advisories for any updated guidance or replacement options, since the advisory states no fix is planned.
- Use the CISA ICS recommended practices and defense-in-depth guidance to compensate for the lack of a vendor patch.
- Treat the affected chargers as higher risk in sites with public, shared, or otherwise unsupervised installation locations.
Evidence notes
The source corpus ties this CVE to Siemens advisory SSA-556937 and CISA advisory ICSA-25-135-08, published on 2025-05-13. The advisory description states: “Affected devices do not contain an Immutable Root of Trust in M0 Hardware. An attacker with physical access to the device could use this to execute arbitrary code.” Siemens’ remediation field says “Currently no fix is planned.” The affected set spans 38 Siemens product entries under the VersiCharge AC Series advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-31929 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-31929
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-31929 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-31929
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-135-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-556937.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-556937.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.