PatchSiren cyber security CVE debrief
CVE-2025-59375 Siemens CVE debrief
CVE-2025-59375 is a denial-of-service issue in libexpat, affecting Hitachi Energy RTU500 series CMU Firmware only when IEC61850 functionality is configured. A small XML document submitted for parsing can cause large dynamic memory allocations, creating an availability risk. The advisory points to firmware updates as the primary fix.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
OT/ICS teams running Hitachi Energy RTU500 series CMU Firmware with IEC61850 configured, along with asset owners, plant operators, SOC analysts, and patch coordinators responsible for those systems.
Technical summary
The advisory states that Expat versions before 2.7.2 can be driven to perform large dynamic memory allocations from a small document submitted for parsing. Hitachi Energy’s advisory scope narrows the impact to systems where IEC61850 functionality is configured. The CVSS vector reflects a network-reachable availability-only condition, with no confidentiality or integrity impact stated.
Defensive priority
High for any deployed RTU500 CMU systems using IEC61850. Prioritize systems that are operationally critical, widely reachable within plant networks, or difficult to restart safely.
Recommended defensive actions
- Update RTU500 series CMU Firmware to version 12.7.8 if you are on the 12.7.x branch.
- Update RTU500 series CMU Firmware to version 13.7.8 or the latest available release for the 13.5.x, 13.6.x, and 13.7.x branches.
- Update RTU500 series CMU Firmware to version 13.8.2 for the 13.8.1 release line.
- Inventory which assets have IEC61850 functionality configured so patching and risk decisions target only affected systems.
- Apply general ICS hardening and segmentation practices from CISA to reduce exposure while remediation is underway.
- Validate updates in a maintenance window and confirm service restoration, since this issue can affect availability.
Evidence notes
Primary evidence comes from CISA CSAF advisory ICSA-26-062-03 (published 2026-02-24, republished 2026-03-03) and its linked Hitachi Energy PSIRT advisory. The advisory text explicitly says libexpat in Expat before 2.7.2 can trigger large dynamic memory allocations via a small document submitted for parsing, and that the product is only affected if IEC61850 functionality is configured. Source metadata in the corpus includes a low-confidence vendor mapping, so the product naming should be treated as advisory-driven rather than inferred from enrichment fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-59375 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-59375
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-59375 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-59375
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.