PatchSiren cyber security CVE debrief
CVE-2025-4517 Siemens CVE debrief
CVE-2025-4517 is a critical arbitrary filesystem write issue described in the supplied CISA/Siemens advisory corpus. The vulnerability is triggered when untrusted tar archives are extracted with Python tarfile APIs using filter="data" or filter="tar". For Python 3.14 and later, the advisory notes that the default filter changed to "data", so code relying on that default can also be exposed. In the Siemens advisory materials republished by CISA, the affected scope maps to multiple Siemens industrial networking products, and the stated remediation is to update affected firmware to V3.3 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-28
- Original CVE updated
- 2026-02-25
- Advisory published
- 2026-01-28
- Advisory updated
- 2026-02-25
Who should care
Siemens RUGGEDCOM and SCALANCE operators, OT/ICS platform owners, and integrators who use the affected firmware or any archive-extraction workflow that relies on Python tarfile filtering. Security teams should also review update pipelines and any tooling that processes untrusted tar archives.
Technical summary
The advisory states that TarFile.extractall() and TarFile.extract() can permit arbitrary writes outside the extraction directory when used with filter="data" or filter="tar". That makes path handling during extraction the key security boundary. The supplied source also calls out Python 3.14’s default filter="data" behavior change, which expands exposure for code that assumed the newer default was safe. Siemens’ published remediation in the corpus is to update affected products to V3.3 or later, with one product entry pointing to additional information.
Defensive priority
Urgent. The supplied CVSS score is 9.4 (Critical), and the remediation is a vendor update rather than a workaround. Prioritize exposure validation and firmware upgrade planning for any affected Siemens deployment, then review archive-handling code paths that may extract untrusted tar content.
Recommended defensive actions
- Inventory Siemens products named in the advisory and confirm whether any affected models or firmware are deployed.
- Apply Siemens’ remediation and update to V3.3 or later for affected products, using the vendor advisory referenced in the corpus.
- Review any Python code or embedded tooling that calls TarFile.extractall() or TarFile.extract() on untrusted archives, especially where filter="data" or filter="tar" is used.
- If Python 3.14 or later is in use, do not assume the default filter="data" is safe for untrusted content; explicitly validate archive-extraction behavior.
- Restrict untrusted archive handling in operational workflows until updates are confirmed, and treat suspicious archive links cautiously during source-distribution evaluation.
- Track the Siemens and CISA advisory pages for product-specific clarification, including any entries that reference additional information rather than a direct firmware version note.
Evidence notes
All statements are drawn from the supplied CSAF source item, its revision history, the Siemens references, and the official CVE/NVD links. The corpus says the issue allows arbitrary filesystem writes outside the extraction directory during tar extraction with filter="data" and applies when filter="tar" is used as well. The source metadata shows initial publication on 2026-01-28 and latest modification on 2026-02-25, with CISA republication updates on 2026-02-12 and 2026-02-24. Remediation in the corpus is firmware update to V3.3 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-4517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-4517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-4517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-4517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.