PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40593 Siemens CVE debrief

CVE-2025-40593 is a medium-severity vulnerability affecting Siemens SIMATIC CN 4100. According to the CISA CSAF advisory, an attacker can store arbitrary files in the device’s SFTP folder and potentially cause a denial-of-service condition. Siemens provides a fix in V4.0 or later.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-08
Original CVE updated
2025-07-08
Advisory published
2025-07-08
Advisory updated
2025-07-08

Who should care

Operators and administrators of Siemens SIMATIC CN 4100 devices, especially environments that expose or rely on the device’s SFTP functionality, should review this advisory promptly. Industrial control and OT teams should also confirm whether the affected product is deployed in production networks.

Technical summary

The advisory describes a network-reachable issue with CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating low attack complexity, required low privileges, no user interaction, and high availability impact. The stated impact is denial of service caused by storing arbitrary files in the device’s SFTP folder. The advisory does not provide additional technical detail beyond that behavior.

Defensive priority

Medium. The issue is publicly disclosed, affects availability, and has a vendor fix available. Prioritize remediation where the product is operationally important or externally reachable.

Recommended defensive actions

  • Update Siemens SIMATIC CN 4100 to V4.0 or later, per the vendor remediation guidance.
  • Restrict access to the device’s SFTP service to only trusted administrative hosts and users.
  • Monitor for unexpected file activity in the SFTP folder and for signs of service disruption.
  • Review OT network segmentation and access controls around the affected device.
  • Validate patching in a maintenance window consistent with industrial operations before deployment.

Evidence notes

All claims in this debrief are taken from the supplied CISA CSAF advisory record for ICSA-25-191-04 and its linked Siemens advisory references. The source describes the issue as arbitrary file storage in the SFTP folder leading to denial of service, and lists the remediation as updating to V4.0 or later. No KEV entry is associated with this CVE in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40593 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40593

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40593 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40593

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-191-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-626991.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-626991.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.