PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-3576 Siemens CVE debrief

CVE-2025-3576 is a medium-severity integrity vulnerability affecting Siemens RUGGEDCOM ROX products when MIT Kerberos GSSAPI messages use RC4-HMAC-MD5. According to the advisory, weaknesses in MD5 checksum design can let an attacker spoof protected messages and forge message integrity codes when RC4 is preferred over stronger encryption types. Siemens and CISA identify affected RUGGEDCOM ROX MX5000 and related models, with remediation available in V2.17.1 or later.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2026-09-01
Advisory published
2025-04-15
Advisory updated
2026-09-01

Who should care

Operators, administrators, and asset owners responsible for Siemens RUGGEDCOM ROX MX5000 and related ROX models should review this advisory, especially if Kerberos/GSSAPI is enabled and RC4 is still allowed or preferred. Security teams supporting industrial or remote-access environments using these devices should confirm upgrade plans and encryption settings.

Technical summary

The advisory describes a spoofing issue in the MIT Kerberos implementation used by affected Siemens RUGGEDCOM ROX products. The weakness is tied to GSSAPI-protected messages that rely on RC4-HMAC-MD5: if RC4 is negotiated ahead of stronger encryption types, an attacker may be able to exploit MD5 collision properties to forge message integrity codes and tamper with message contents. The published CVSS vector reflects network attackability with high complexity and an integrity impact, without direct confidentiality or availability impact.

Defensive priority

Medium priority. The issue is exploitable over the network but requires high attack complexity, and the published impact is limited to integrity. Prioritize if the affected devices are exposed to untrusted networks or if RC4 remains enabled/preferred.

Recommended defensive actions

  • Update Siemens RUGGEDCOM ROX devices to V2.17.1 or later, as directed by the vendor advisory.
  • Verify whether RC4-HMAC-MD5 is enabled or preferred in Kerberos/GSSAPI configurations and switch to stronger encryption types where possible.
  • Inventory affected RUGGEDCOM ROX models and versions, including MX5000 and the related ROX families named in the advisory.
  • Review any services or integrations that depend on Kerberos-protected messaging for message integrity or device authentication.
  • Track Siemens ProductCERT and CISA advisory updates for any additional guidance or clarifications.

Evidence notes

The source corpus identifies the advisory as ICSA-26-134-16 and states that CISA published it on 2026-05-12, then republished Siemens ProductCERT SSA-577017 on 2026-05-14. The affected product list in the advisory includes Siemens RUGGEDCOM ROX MX5000 and related ROX models, with a remediation to update to V2.17.1 or later. The CVE description supplied in the corpus attributes the issue to MIT Kerberos RC4-HMAC-MD5 message spoofing via MD5 checksum weaknesses. No exploit steps or code are included here.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-3576 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-3576

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-3576 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3576

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.