PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-4517 Siemens CVE debrief

CVE-2025-4517 is a critical arbitrary filesystem write issue described in the supplied CISA/Siemens advisory corpus. The vulnerability is triggered when untrusted tar archives are extracted with Python tarfile APIs using filter="data" or filter="tar". For Python 3.14 and later, the advisory notes that the default filter changed to "data", so code relying on that default can also be exposed. In the Siemens advisory materials republished by CISA, the affected scope maps to multiple Siemens industrial networking products, and the stated remediation is to update affected firmware to V3.3 or later.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-28
Original CVE updated
2026-02-25
Advisory published
2026-01-28
Advisory updated
2026-02-25

Who should care

Siemens RUGGEDCOM and SCALANCE operators, OT/ICS platform owners, and integrators who use the affected firmware or any archive-extraction workflow that relies on Python tarfile filtering. Security teams should also review update pipelines and any tooling that processes untrusted tar archives.

Technical summary

The advisory states that TarFile.extractall() and TarFile.extract() can permit arbitrary writes outside the extraction directory when used with filter="data" or filter="tar". That makes path handling during extraction the key security boundary. The supplied source also calls out Python 3.14’s default filter="data" behavior change, which expands exposure for code that assumed the newer default was safe. Siemens’ published remediation in the corpus is to update affected products to V3.3 or later, with one product entry pointing to additional information.

Defensive priority

Urgent. The supplied CVSS score is 9.4 (Critical), and the remediation is a vendor update rather than a workaround. Prioritize exposure validation and firmware upgrade planning for any affected Siemens deployment, then review archive-handling code paths that may extract untrusted tar content.

Recommended defensive actions

  • Inventory Siemens products named in the advisory and confirm whether any affected models or firmware are deployed.
  • Apply Siemens’ remediation and update to V3.3 or later for affected products, using the vendor advisory referenced in the corpus.
  • Review any Python code or embedded tooling that calls TarFile.extractall() or TarFile.extract() on untrusted archives, especially where filter="data" or filter="tar" is used.
  • If Python 3.14 or later is in use, do not assume the default filter="data" is safe for untrusted content; explicitly validate archive-extraction behavior.
  • Restrict untrusted archive handling in operational workflows until updates are confirmed, and treat suspicious archive links cautiously during source-distribution evaluation.
  • Track the Siemens and CISA advisory pages for product-specific clarification, including any entries that reference additional information rather than a direct firmware version note.

Evidence notes

All statements are drawn from the supplied CSAF source item, its revision history, the Siemens references, and the official CVE/NVD links. The corpus says the issue allows arbitrary filesystem writes outside the extraction directory during tar extraction with filter="data" and applies when filter="tar" is used as well. The source metadata shows initial publication on 2026-01-28 and latest modification on 2026-02-25, with CISA republication updates on 2026-02-12 and 2026-02-24. Remediation in the corpus is firmware update to V3.3 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-4517 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-4517

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-4517 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-4517

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.