PatchSiren cyber security CVE debrief
CVE-2025-59392 Siemens CVE debrief
A physical-access vulnerability in Elspec G5 devices allows an attacker with physical proximity to reset the administrative password using a USB drive containing a publicly documented reset string. The vulnerability affects devices running firmware through version 1.2.2.19. The CVSS v3.1 vector (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects that while physical presence is required, successful exploitation yields complete compromise of confidentiality, integrity, and availability. The attack complexity is low and no user interaction is required beyond the physical insertion of the prepared USB device.
- Vendor
- Siemens
- Product
- Energy Services
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2025-12-09
- Advisory published
- 2025-12-09
- Advisory updated
- 2025-12-09
Who should care
Operational technology security teams, industrial control system administrators, critical infrastructure operators using Elspec G5 devices for power quality monitoring, and organizations with physical security responsibilities for substation or plant-floor equipment.
Technical summary
The Elspec G5 firmware through 1.2.2.19 implements a password recovery mechanism that can be triggered by inserting a USB drive containing a specific reset string. This string is publicly documented, enabling any individual with physical device access to reset administrative credentials without authentication. The vulnerability is classified as MEDIUM severity (CVSS 6.8) due to the physical access prerequisite, though impact is rated HIGH for confidentiality, integrity, and availability if exploited. The attack requires no privileges or user interaction beyond physical presence.
Defensive priority
medium
Recommended defensive actions
- Update affected Elspec G5 devices to G5DFR V1.2.3.13 or later
- Restrict physical access to Elspec G5 devices to authorized personnel only
- Monitor for unauthorized USB device connections in operational technology environments
- Review and implement CISA ICS recommended practices for defense-in-depth strategies
- Verify firmware version on all deployed Elspec G5 units and document asset inventory
Evidence notes
CISA published advisory ICSA-25-345-08 on 2025-12-09, confirming the vulnerability and vendor fix availability. Siemens has issued security advisory SSA-734261 with remediation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-59392 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-59392
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-59392 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-59392
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-734261.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-734261.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.