PatchSiren cyber security CVE debrief
CVE-2025-49796 Siemens CVE debrief
CVE-2025-49796 is a critical memory corruption issue in libxml2 that can be triggered while processing certain sch:name elements from a crafted XML file. In the Siemens advisory republished by CISA, the issue is tied to multiple RUGGEDCOM ROX products and can lead to crashes, denial of service, or other undefined behavior. Siemens’ remediation is to update to V2.17.1 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-16
- Original CVE updated
- 2026-09-28
- Advisory published
- 2025-06-16
- Advisory updated
- 2026-09-28
Who should care
OT/ICS operators, integrators, and maintainers of the Siemens RUGGEDCOM ROX devices listed in the advisory, especially where systems process untrusted or externally supplied XML.
Technical summary
According to the advisory text, processing specific sch:name elements in input XML can corrupt memory in libxml2. The supplied CVSS vector indicates a network-reachable, low-complexity issue with no privileges or user interaction required, and with high integrity and availability impact. The practical result can be application or device crashes and potentially broader undefined behavior due to memory corruption.
Defensive priority
Urgent. Treat as a critical patching item and validate whether any affected RUGGEDCOM ROX device or workflow parses XML exposed to untrusted input.
Recommended defensive actions
- Update affected Siemens RUGGEDCOM ROX products to V2.17.1 or later, per Siemens ProductCERT guidance.
- Inventory RUGGEDCOM ROX systems and confirm whether they fall under the advisory's affected product list.
- Reduce exposure of XML parsing paths to untrusted input wherever operationally possible.
- Apply defense-in-depth controls around industrial devices, including network segmentation and strict access controls.
- Monitor affected systems for crashes or abnormal behavior that could indicate malformed XML handling issues.
Evidence notes
Source evidence comes from CISA advisory ICSA-26-134-16 republishing Siemens ProductCERT SSA-577017 on 2026-05-14, with the initial advisory publication dated 2026-05-12. The advisory text states that processing certain sch:name elements in input XML can trigger memory corruption in libxml2, and the remediation listed is to update to V2.17.1 or later. The CVSS vector supplied with the advisory is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-49796 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-49796
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-49796 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49796
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.