PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38231 Siemens CVE debrief

CVE-2025-38231 is a Linux kernel nfsd availability issue described in Siemens/CISA advisories for several SIMATIC S7-1500 CPU MFP products. The flaw can lead to a NULL pointer dereference when delayed work starts before nfsd_ssc initialization completes, which may happen if the kernel is waiting too long for userspace responses. The advisory states that no fix is currently available and recommends compensating controls.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Operators and maintainers of the listed Siemens SIMATIC S7-1500 CPU 1518/1518F MFP variants, OT/ICS defenders, and teams responsible for the embedded GNU/Linux subsystem or local shell access on these devices should prioritize this advisory.

Technical summary

According to the source description, nfs4_state_start_net() may start laundromat_work before nfsd_ssc is initialized. laundromat_work can later reach nfsd4_ssc_expire_umount via nfs4_laundromat, producing a NULL pointer dereference if nfsd_ssc is not ready. The condition is more likely when the kernel blocks on userspace completion paths, delaying initialization long enough for the delayed work to run first. The source characterizes the issue as local, with availability impact, and the linked CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Defensive priority

Medium to High for affected assets: the scored severity is Medium (CVSS 5.5), but the impact is a kernel availability fault on industrial devices and the source says no fix is available yet.

Recommended defensive actions

  • Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only, as recommended in the advisory.
  • Only build and run applications from trusted sources on the affected devices.
  • Treat the listed SIMATIC S7-1500 CPU MFP variants as affected until Siemens publishes a fix or updated guidance.
  • Reduce opportunities for local triggering by minimizing unnecessary local users, services, and administrative access on the device.
  • Monitor the Siemens ProductCERT and CISA advisory pages for remediation updates and revision changes.
  • Plan maintenance windows and operational contingencies for potential availability loss, since the issue can lead to a kernel NULL dereference.
  • Apply Siemens-approved compensating controls and validation before introducing any new software or configuration changes.
  • Use CISA ICS recommended practices and defense-in-depth guidance to limit the blast radius of a device crash.

Evidence notes

The supplied Siemens/CISA CSAF advisory (ICSA-25-162-05 / SSA-082556) lists affected products as SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0, 6ES7518-4AX00-1AC0), SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0, 6ES7518-4FX00-1AC0), and SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0). The source description states the flaw is a Linux kernel nfsd NULL dereference caused by laundromat_work reaching nfsd_ssc before initialization completes, especially under delayed userspace response paths. The advisory remediation section says 'Currently no fix is available' and suggests restricting shell access and using trusted software only. The CVSS vector provided in the source is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, and the CVE is not marked as KEV in the supplied data. Published date used here is 2025-06-10; later advisory revisions are update context, not the original CVE date.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38231 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38231

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38231 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38231

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.