PatchSiren cyber security CVE debrief
CVE-2025-39787 Siemens CVE debrief
CVE-2025-39787 describes an out-of-bounds read in the Linux kernel's soc:qcom:mdt_loader path when parsing ELF headers. In the CISA/Siemens advisory context, the fix is to ensure the firmware buffer is validated before iterating and to verify e_phentsize and e_shentsize so header traversal steps remain safe. Siemens’ remediation is to update SIMATIC CN 4100 to V5.0 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
OT/ICS teams operating Siemens SIMATIC CN 4100 systems, and administrators of any Linux-based firmware-loading workflow that may process untrusted MDT/ELF buffers.
Technical summary
The vulnerability is a bounds-checking flaw in mdt_loader's ELF header traversal. When the loader is used outside remoteproc, the ELF header may not be sanitized beforehand, so the code can read past the end of the firmware buffer while iterating header entries. The advisory also notes validation of e_phentsize and e_shentsize to ensure the traversal step size assumptions are correct. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5, medium), indicating a local availability impact.
Defensive priority
Medium
Recommended defensive actions
- Confirm whether any deployed Siemens SIMATIC CN 4100 devices are on a version earlier than V5.0.
- Apply Siemens' remediation and move to V5.0 or later where feasible.
- If immediate upgrading is not possible, follow Siemens/CISA guidance for any available vendor backport or interim mitigation.
- Restrict firmware-loading and update interfaces to trusted administrators and trusted networks.
- Track asset inventory for Linux kernel components that parse firmware buffers or ELF headers from external sources.
Evidence notes
This debrief is based on CISA CSAF ICSA-26-134-10, published 2026-05-12 and republished on 2026-05-14 from Siemens ProductCERT SSA-032379. The advisory text states that the MDT loader may read past the end of the firmware buffer while iterating over the ELF header and that e_phentsize/e_shentsize are validated in the fix. The supplied advisory data lists CVSS 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), remediation to Siemens SIMATIC CN 4100 V5.0 or later, and no KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39787 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39787
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39787 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39787
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.