PatchSiren cyber security CVE debrief
CVE-2025-32989 Siemens CVE debrief
CVE-2025-32989 is a network-reachable information-disclosure issue in GnuTLS certificate parsing that Siemens mapped to specific SIMATIC S7-1500 CPU models in its ProductCERT advisory. A malformed Certificate Transparency Signed Certificate Timestamp (SCT) extension can trigger a heap-buffer-overread during X.509 parsing, potentially exposing confidential data. Siemens lists no fix at this time, so affected environments should use compensating controls and track advisory updates.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-10
- Original CVE updated
- 2026-09-01
- Advisory published
- 2025-07-10
- Advisory updated
- 2026-09-01
Who should care
Operators and maintainers of the listed Siemens SIMATIC S7-1500 CPU 1518/1518F MFP models, especially where the embedded GNU/Linux subsystem or certificate-verifying applications are in use. Industrial control system defenders should also care because Siemens currently lists no fix and recommends only mitigation steps.
Technical summary
The underlying flaw is a heap-buffer-overread in GnuTLS while handling the Certificate Transparency Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. The advisory states that a malformed SCT extension with OID 1.3.6.1.4.1.11129.2.4.2 can cause sensitive data exposure when certificates are verified incorrectly. In the Siemens advisory, the issue is associated with five SIMATIC S7-1500 CPU product variants. The published CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (5.3, Medium).
Defensive priority
Medium. Prioritize for affected Siemens CPU deployments because the issue is externally reachable in the advisory’s scoring, confidentiality is impacted, and Siemens lists no fix. Apply compensating controls and monitor for a vendor update.
Recommended defensive actions
- Confirm whether any of the five listed Siemens CPU models are deployed in your environment.
- Treat the issue as mitigation-only for now; Siemens states that no fix is available at present.
- Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on affected systems.
- Track Siemens ProductCERT and CISA advisory updates for a future remediation or revision.
- Use ICS defense-in-depth and other recommended practices to reduce exposure while the issue remains unresolved.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-162-05 and Siemens ProductCERT advisory SSA-082556. The source item was first published on 2025-06-10, with later CISA republication updates through 2026-05-14. The advisory’s affected-product list includes five Siemens SIMATIC/SIPLUS CPU variants, and the remediation section explicitly states that no fix is currently available.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-32989 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-32989
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-32989 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32989
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.