PatchSiren cyber security CVE debrief
CVE-2025-38086 Siemens CVE debrief
CVE-2025-38086 is a HIGH-severity Linux kernel issue tied to Siemens industrial OT firmware. In the ch9200 MDIO read path, an error from control_read() is not checked, so an uninitialized local buffer can be read during mii_nway_restart(). Siemens’ advisory, republished by CISA, says affected products should be updated to V3.3 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-28
- Original CVE updated
- 2026-02-25
- Advisory published
- 2026-01-28
- Advisory updated
- 2026-02-25
Who should care
Siemens SINEC OS operators, OT/ICS administrators, and asset owners responsible for the listed SCALANCE and RUGGEDCOM product families should review applicability and patch plans.
Technical summary
The issue occurs when ch9200_mdio_read() calls control_read() and ignores its return value. If control_read() does not fully initialize the local buffer, later code can access buff[0] and buff[1] anyway, resulting in uninitialized data access during mii_nway_restart(). The supplied CVSS vector indicates local access, low privileges, and high attack complexity (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Defensive priority
High for affected Siemens OT environments. Verify exposure quickly and apply the vendor fix because the advisory lists a corrected version and the flaw can affect core device firmware behavior.
Recommended defensive actions
- Check whether any Siemens devices in your inventory match the affected products listed in SSA-089022 / ICSA-26-043-06.
- Apply the vendor remediation: update to V3.3 or later for affected products, per Siemens guidance.
- If immediate patching is not possible, restrict local administrative access, follow OT segmentation and defense-in-depth practices, and monitor the affected assets closely.
- Confirm the exact firmware branch and model mapping before maintenance, because the source revision history notes a scope clarification for SINEC OS firmware impact.
Evidence notes
Source corpus places publication at 2026-01-28 and last update at 2026-02-25. The CISA CSAF advisory ICSA-26-043-06 republishes Siemens ProductCERT SSA-089022 and includes a remediation of V3.3 or later. The description explicitly states that ch9200_mdio_read() ignores the return value of control_read(), enabling access to an uninitialized buffer. The source revision history also notes a clarification that only SINEC OS firmware is impacted. No KEV entry is present in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38086 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38086
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38086 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38086
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.