PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39824 Siemens CVE debrief

CVE-2025-39824 appears in a CISA CSAF advisory published on 2026-05-12 and republished on 2026-05-14. The advisory maps the issue to Siemens SIMATIC CN 4100 versions before 5.0 and recommends updating to V5.0 or later. However, the embedded vulnerability text describes a Linux kernel HID use-after-free condition triggered by a crafted HID descriptor, so the product-to-vulnerability mapping in this source should be validated before operational decisions are made.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Operators and maintainers of Siemens SIMATIC CN 4100 deployments, OT security teams, and asset owners that allow connection of external HID devices. Because the source record is internally inconsistent, vulnerability triage should include confirming whether the advisory truly applies to the deployed Siemens device and software version.

Technical summary

The source description says the issue is a use-after-free in Linux kernel HID input handling. During hid_hw_start(), hidinput_connect() processes reports and may free an input device if capability bitmaps are never populated; later writes to the freed device name can trigger a UAF. The advisory text states that a malicious HID device with a specially crafted descriptor can trigger the condition. The source also provides a CVSS v3.1 vector of AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H with a score of 7.0.

Defensive priority

High for any environment that matches the Siemens advisory scope or that accepts untrusted HID peripherals; otherwise, treat as a validation-priority issue because the source record’s product and vulnerability descriptions do not align cleanly.

Recommended defensive actions

  • Verify whether your environment includes Siemens SIMATIC CN 4100 systems at versions earlier than V5.0.
  • Apply the vendor-recommended update to V5.0 or later where applicable.
  • Confirm the advisory/product mapping against Siemens ProductCERT and CISA references before scheduling remediation.
  • Restrict physical access to systems that can accept external HID devices and limit attachment of untrusted peripherals.
  • Follow CISA industrial control system recommended practices for segmentation, access control, and defense in depth.

Evidence notes

Source item metadata identifies CISA CSAF advisory ICSA-26-134-10, published 2026-05-12 and republished 2026-05-14 with Siemens ProductCERT SSA-032379 content. The advisory metadata lists productNames as Siemens / SIMATIC CN 4100 / vers:intdot/<5.0 and remediates with "Update to V5.0 or later version." The vulnerability description embedded in the record is truncated, but it clearly discusses a Linux kernel HID asus use-after-free triggered by a crafted HID descriptor and includes a KASAN splat. Because the product mapping and vulnerability narrative conflict, this record should be treated as low-confidence and validated against the vendor advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39824 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39824

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39824 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39824

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.