PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39693 Siemens CVE debrief

CVE-2025-39693 is a medium-severity availability issue published by CISA on 2026-05-12 and republished with Siemens ProductCERT material on 2026-05-14. The supplied advisory says the fix is to update Siemens SIMATIC CN 4100 to V5.0 or later. The underlying technical issue described in the record is a NULL pointer dereference risk in Linux kernel drm/amd/display code.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Owners and operators of Siemens SIMATIC CN 4100 deployments, especially teams responsible for patching, asset inventory, and validation in industrial environments. Linux kernel maintainers and integrators should also note the code-level NULL dereference described in the advisory record.

Technical summary

The source corpus describes a kernel-level NULL pointer dereference condition in drm/amd/display. Specifically, drm_atomic_get_new_connector_state() or drm_atomic_get_old_connector_state() can reportedly return NULL, and the fix is to check the return values before dereference. The CVSS vector in the supplied data is AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access with some privileges and an availability impact only.

Defensive priority

Medium. The impact is availability-focused and the CVSS score is 4.7, but the advisory is tied to industrial-control product guidance and should be handled through vendor-recommended updating and validation.

Recommended defensive actions

  • Update Siemens SIMATIC CN 4100 to V5.0 or later, per the Siemens remediation guidance in the supplied advisory.
  • Verify whether your deployment matches the affected product scope before scheduling maintenance or applying updates.
  • Review the Siemens and CISA advisory references for any deployment-specific instructions or constraints.
  • Track affected assets for any crashes or service interruptions consistent with a NULL pointer dereference until remediation is complete.
  • Confirm there is no CISA KEV listing in your internal prioritization flow for this CVE, based on the supplied data.

Evidence notes

The source metadata contains a mismatch: the CVE description references a Linux kernel drm/amd/display fix, while the advisory metadata and remediation point to Siemens SIMATIC CN 4100 and Siemens ProductCERT advisory SSA-032379. Because of this inconsistency, the product association should be treated as low-confidence and verified against the official Siemens/CISA references before operational action.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39693 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39693

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39693 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39693

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.