PatchSiren cyber security CVE debrief
CVE-2025-39824 Siemens CVE debrief
CVE-2025-39824 appears in a CISA CSAF advisory published on 2026-05-12 and republished on 2026-05-14. The advisory maps the issue to Siemens SIMATIC CN 4100 versions before 5.0 and recommends updating to V5.0 or later. However, the embedded vulnerability text describes a Linux kernel HID use-after-free condition triggered by a crafted HID descriptor, so the product-to-vulnerability mapping in this source should be validated before operational decisions are made.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of Siemens SIMATIC CN 4100 deployments, OT security teams, and asset owners that allow connection of external HID devices. Because the source record is internally inconsistent, vulnerability triage should include confirming whether the advisory truly applies to the deployed Siemens device and software version.
Technical summary
The source description says the issue is a use-after-free in Linux kernel HID input handling. During hid_hw_start(), hidinput_connect() processes reports and may free an input device if capability bitmaps are never populated; later writes to the freed device name can trigger a UAF. The advisory text states that a malicious HID device with a specially crafted descriptor can trigger the condition. The source also provides a CVSS v3.1 vector of AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H with a score of 7.0.
Defensive priority
High for any environment that matches the Siemens advisory scope or that accepts untrusted HID peripherals; otherwise, treat as a validation-priority issue because the source record’s product and vulnerability descriptions do not align cleanly.
Recommended defensive actions
- Verify whether your environment includes Siemens SIMATIC CN 4100 systems at versions earlier than V5.0.
- Apply the vendor-recommended update to V5.0 or later where applicable.
- Confirm the advisory/product mapping against Siemens ProductCERT and CISA references before scheduling remediation.
- Restrict physical access to systems that can accept external HID devices and limit attachment of untrusted peripherals.
- Follow CISA industrial control system recommended practices for segmentation, access control, and defense in depth.
Evidence notes
Source item metadata identifies CISA CSAF advisory ICSA-26-134-10, published 2026-05-12 and republished 2026-05-14 with Siemens ProductCERT SSA-032379 content. The advisory metadata lists productNames as Siemens / SIMATIC CN 4100 / vers:intdot/<5.0 and remediates with "Update to V5.0 or later version." The vulnerability description embedded in the record is truncated, but it clearly discusses a Linux kernel HID asus use-after-free triggered by a crafted HID descriptor and includes a KASAN splat. Because the product mapping and vulnerability narrative conflict, this record should be treated as low-confidence and validated against the vendor advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39824 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39824
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39824 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39824
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.