PatchSiren cyber security CVE debrief
CVE-2025-39693 Siemens CVE debrief
CVE-2025-39693 is a medium-severity availability issue published by CISA on 2026-05-12 and republished with Siemens ProductCERT material on 2026-05-14. The supplied advisory says the fix is to update Siemens SIMATIC CN 4100 to V5.0 or later. The underlying technical issue described in the record is a NULL pointer dereference risk in Linux kernel drm/amd/display code.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Owners and operators of Siemens SIMATIC CN 4100 deployments, especially teams responsible for patching, asset inventory, and validation in industrial environments. Linux kernel maintainers and integrators should also note the code-level NULL dereference described in the advisory record.
Technical summary
The source corpus describes a kernel-level NULL pointer dereference condition in drm/amd/display. Specifically, drm_atomic_get_new_connector_state() or drm_atomic_get_old_connector_state() can reportedly return NULL, and the fix is to check the return values before dereference. The CVSS vector in the supplied data is AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access with some privileges and an availability impact only.
Defensive priority
Medium. The impact is availability-focused and the CVSS score is 4.7, but the advisory is tied to industrial-control product guidance and should be handled through vendor-recommended updating and validation.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V5.0 or later, per the Siemens remediation guidance in the supplied advisory.
- Verify whether your deployment matches the affected product scope before scheduling maintenance or applying updates.
- Review the Siemens and CISA advisory references for any deployment-specific instructions or constraints.
- Track affected assets for any crashes or service interruptions consistent with a NULL pointer dereference until remediation is complete.
- Confirm there is no CISA KEV listing in your internal prioritization flow for this CVE, based on the supplied data.
Evidence notes
The source metadata contains a mismatch: the CVE description references a Linux kernel drm/amd/display fix, while the advisory metadata and remediation point to Siemens SIMATIC CN 4100 and Siemens ProductCERT advisory SSA-032379. Because of this inconsistency, the product association should be treated as low-confidence and verified against the official Siemens/CISA references before operational action.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39693 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39693
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39693 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39693
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.