PatchSiren cyber security CVE debrief
CVE-2025-39702 Siemens CVE debrief
CVE-2025-39702 is a high-severity timing issue in the Linux kernel’s IPv6 segment routing path. The fix changes MAC comparison to a constant-time helper so attackers cannot use timing differences to learn information. In the supplied advisory corpus, CISA republishes Siemens guidance for SIMATIC CN 4100 systems that include affected software, with remediation to update to V5.0 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
OT and industrial control system operators using Siemens SIMATIC CN 4100 devices, administrators responsible for embedded Linux-based appliance software, and security teams that manage vendor advisories and patch validation for production control environments.
Technical summary
The underlying bug is a non-constant-time MAC comparison in IPv6 segment routing. Because MACs were not compared in constant time, an attacker with the prerequisites reflected in the CVSS vector could potentially infer information through timing differences. The published vector indicates local access and low privileges are required, with confidentiality and availability impact but no integrity impact. The advisory corpus ties the issue to Siemens SIMATIC CN 4100 product guidance and recommends updating to V5.0 or later.
Defensive priority
High for any affected Siemens SIMATIC CN 4100 deployment or downstream build that includes the vulnerable code path. Even though the issue is not marked as KEV, the combination of high CVSS severity, local attack prerequisites, and exposure in an OT-adjacent product warrants prompt validation and patch planning.
Recommended defensive actions
- Confirm whether any deployed Siemens SIMATIC CN 4100 systems are on versions earlier than V5.0.
- Apply the vendor remediation to update to V5.0 or later.
- Review downstream or embedded Linux images that may include the affected IPv6 segment routing code path.
- Restrict local access and privileged accounts on systems that cannot be updated immediately.
- Track the Siemens and CISA advisories for any follow-up guidance or revised product scope.
- Validate patches in a maintenance window before broad rollout in production OT environments.
Evidence notes
This debrief is based only on the supplied CISA CSAF source item and its referenced Siemens advisory links. The source description states: “In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time.” The same source corpus lists remediation as updating to V5.0 or later. The product mapping in the supplied metadata is low-confidence and marked needsReview, so the underlying code issue should be treated as Linux-kernel based while the affected product scope should be confirmed against the vendor advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39702 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39702
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39702 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39702
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.