PatchSiren cyber security CVE debrief
CVE-2025-40593 Siemens CVE debrief
CVE-2025-40593 is a medium-severity vulnerability affecting Siemens SIMATIC CN 4100. According to the CISA CSAF advisory, an attacker can store arbitrary files in the device’s SFTP folder and potentially cause a denial-of-service condition. Siemens provides a fix in V4.0 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-08
- Original CVE updated
- 2025-07-08
- Advisory published
- 2025-07-08
- Advisory updated
- 2025-07-08
Who should care
Operators and administrators of Siemens SIMATIC CN 4100 devices, especially environments that expose or rely on the device’s SFTP functionality, should review this advisory promptly. Industrial control and OT teams should also confirm whether the affected product is deployed in production networks.
Technical summary
The advisory describes a network-reachable issue with CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating low attack complexity, required low privileges, no user interaction, and high availability impact. The stated impact is denial of service caused by storing arbitrary files in the device’s SFTP folder. The advisory does not provide additional technical detail beyond that behavior.
Defensive priority
Medium. The issue is publicly disclosed, affects availability, and has a vendor fix available. Prioritize remediation where the product is operationally important or externally reachable.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V4.0 or later, per the vendor remediation guidance.
- Restrict access to the device’s SFTP service to only trusted administrative hosts and users.
- Monitor for unexpected file activity in the SFTP folder and for signs of service disruption.
- Review OT network segmentation and access controls around the affected device.
- Validate patching in a maintenance window consistent with industrial operations before deployment.
Evidence notes
All claims in this debrief are taken from the supplied CISA CSAF advisory record for ICSA-25-191-04 and its linked Siemens advisory references. The source describes the issue as arbitrary file storage in the SFTP folder leading to denial of service, and lists the remediation as updating to V4.0 or later. No KEV entry is associated with this CVE in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40593 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40593
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40593 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40593
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-191-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-626991.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-626991.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.