PatchSiren cyber security CVE debrief
CVE-2025-40937 Siemens CVE debrief
CVE-2025-40937 affects Siemens SIMATIC CN 4100 and was publicly published on 2025-12-09. According to the CISA CSAF advisory, the application does not properly validate input parameters in its REST API, which can lead to improper handling of unexpected arguments. Siemens and CISA describe the impact as a condition that could allow an authenticated attacker to execute arbitrary code with limited privileges. Siemens provides a fix in version V4.0.1 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2025-12-09
- Advisory published
- 2025-12-09
- Advisory updated
- 2025-12-09
Who should care
Organizations running Siemens SIMATIC CN 4100, especially industrial control system operators, plant administrators, and security teams responsible for authenticated service access and vendor patch management.
Technical summary
The advisory describes a REST API input validation weakness in SIMATIC CN 4100. The CVSS vector provided is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L, indicating network-reachable impact, low attack complexity, and required low privileges. The stated outcome is possible arbitrary code execution with limited privileges through improper handling of unexpected arguments.
Defensive priority
High. The CVSS score is 8.3 and the affected product is an ICS-related Siemens system with a vendor fix available. Prioritize patching and exposure reduction for any deployments where authenticated REST API access is reachable.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V4.0.1 or later as recommended by the vendor.
- Review which administrators or services can authenticate to the product's REST API and restrict access to the minimum necessary.
- Apply industrial-control defense-in-depth practices and limit network reachability to management interfaces where possible.
- Monitor Siemens and CISA advisory channels for any follow-on guidance related to ICSA-26-015-12 / SSA-416652.
- Validate that asset inventories and patch records reflect the affected product and the remediation version.
Evidence notes
Source details come from the supplied CISA CSAF record for ICSA-26-015-12 and the referenced Siemens advisory SSA-416652. The advisory states the REST API parameter-validation issue and the potential for authenticated arbitrary code execution with limited privileges. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L, and the remediation listed is V4.0.1 or later. KEV status in the supplied enrichment is false.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40937 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40937
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40937 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40937
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-416652.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-416652.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-015-12.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.