PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-49796 Siemens CVE debrief

CVE-2025-49796 is a critical memory corruption issue in libxml2 that can be triggered while processing certain sch:name elements from a crafted XML file. In the Siemens advisory republished by CISA, the issue is tied to multiple RUGGEDCOM ROX products and can lead to crashes, denial of service, or other undefined behavior. Siemens’ remediation is to update to V2.17.1 or later.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-16
Original CVE updated
2026-09-28
Advisory published
2025-06-16
Advisory updated
2026-09-28

Who should care

OT/ICS operators, integrators, and maintainers of the Siemens RUGGEDCOM ROX devices listed in the advisory, especially where systems process untrusted or externally supplied XML.

Technical summary

According to the advisory text, processing specific sch:name elements in input XML can corrupt memory in libxml2. The supplied CVSS vector indicates a network-reachable, low-complexity issue with no privileges or user interaction required, and with high integrity and availability impact. The practical result can be application or device crashes and potentially broader undefined behavior due to memory corruption.

Defensive priority

Urgent. Treat as a critical patching item and validate whether any affected RUGGEDCOM ROX device or workflow parses XML exposed to untrusted input.

Recommended defensive actions

  • Update affected Siemens RUGGEDCOM ROX products to V2.17.1 or later, per Siemens ProductCERT guidance.
  • Inventory RUGGEDCOM ROX systems and confirm whether they fall under the advisory's affected product list.
  • Reduce exposure of XML parsing paths to untrusted input wherever operationally possible.
  • Apply defense-in-depth controls around industrial devices, including network segmentation and strict access controls.
  • Monitor affected systems for crashes or abnormal behavior that could indicate malformed XML handling issues.

Evidence notes

Source evidence comes from CISA advisory ICSA-26-134-16 republishing Siemens ProductCERT SSA-577017 on 2026-05-14, with the initial advisory publication dated 2026-05-12. The advisory text states that processing certain sch:name elements in input XML can trigger memory corruption in libxml2, and the remediation listed is to update to V2.17.1 or later. The CVSS vector supplied with the advisory is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-49796 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-49796

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-49796 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49796

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.