PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39702 Siemens CVE debrief

CVE-2025-39702 is a high-severity timing issue in the Linux kernel’s IPv6 segment routing path. The fix changes MAC comparison to a constant-time helper so attackers cannot use timing differences to learn information. In the supplied advisory corpus, CISA republishes Siemens guidance for SIMATIC CN 4100 systems that include affected software, with remediation to update to V5.0 or later.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

OT and industrial control system operators using Siemens SIMATIC CN 4100 devices, administrators responsible for embedded Linux-based appliance software, and security teams that manage vendor advisories and patch validation for production control environments.

Technical summary

The underlying bug is a non-constant-time MAC comparison in IPv6 segment routing. Because MACs were not compared in constant time, an attacker with the prerequisites reflected in the CVSS vector could potentially infer information through timing differences. The published vector indicates local access and low privileges are required, with confidentiality and availability impact but no integrity impact. The advisory corpus ties the issue to Siemens SIMATIC CN 4100 product guidance and recommends updating to V5.0 or later.

Defensive priority

High for any affected Siemens SIMATIC CN 4100 deployment or downstream build that includes the vulnerable code path. Even though the issue is not marked as KEV, the combination of high CVSS severity, local attack prerequisites, and exposure in an OT-adjacent product warrants prompt validation and patch planning.

Recommended defensive actions

  • Confirm whether any deployed Siemens SIMATIC CN 4100 systems are on versions earlier than V5.0.
  • Apply the vendor remediation to update to V5.0 or later.
  • Review downstream or embedded Linux images that may include the affected IPv6 segment routing code path.
  • Restrict local access and privileged accounts on systems that cannot be updated immediately.
  • Track the Siemens and CISA advisories for any follow-up guidance or revised product scope.
  • Validate patches in a maintenance window before broad rollout in production OT environments.

Evidence notes

This debrief is based only on the supplied CISA CSAF source item and its referenced Siemens advisory links. The source description states: “In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time.” The same source corpus lists remediation as updating to V5.0 or later. The product mapping in the supplied metadata is low-confidence and marked needsReview, so the underlying code issue should be treated as Linux-kernel based while the affected product scope should be confirmed against the vendor advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39702 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39702

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39702 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39702

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.