PatchSiren cyber security CVE debrief
CVE-2025-64756 Siemens CVE debrief
CVE-2025-64756 is a high-severity command-injection issue in a shell-based filename processing path. When the affected -c/--cmd flow is used, matched filenames are passed to a shell with shell: true; if an attacker can influence filenames, shell metacharacters can trigger arbitrary command execution under the user or CI account’s privileges. The supplied CSAF record ties the CVE to Siemens SIDIS Prime and lists V4.0.800 or later as the remediation target.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-03-12
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-03-12
Who should care
Siemens SIDIS Prime operators, integrators, and CI/CD administrators who process untrusted or externally supplied filenames with the affected command path.
Technical summary
The source advisory describes a command-injection flaw in glob-style command execution: filenames matched by patterns are forwarded to a shell with shell: true, so malicious filenames can alter command behavior and execute arbitrary commands. In the supplied CSAF record, the CVE is associated with Siemens SIDIS Prime and the remediation is V4.0.800 or later; follow the vendor advisory path for upgrade guidance and validate any affected automation that invokes the command flow.
Defensive priority
High — arbitrary command execution is possible when untrusted filenames reach the affected command path, including in CI or automation contexts.
Recommended defensive actions
- Update Siemens SIDIS Prime to V4.0.800 or later as directed by the advisory.
- Do not process attacker-controlled or untrusted filenames through the affected -c/--cmd workflow until patched.
- Review CI jobs, service accounts, and automation that invoke the affected command path and reduce privileges where possible.
- Add detection for unexpected child processes or shell activity around filename-processing jobs and investigate anomalies promptly.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-071-03, published 2026-03-10 and republished 2026-03-12, which references Siemens ProductCERT SSA-485750. The source description states that matched filenames are passed to a shell with shell: true and that malicious names can trigger command injection. The supplied record also maps remediation to Siemens SIDIS Prime V4.0.800 or later. Because the advisory text and product-tree context are not perfectly aligned, the vendor advisory and CISA CSAF were treated as the primary evidence sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64756 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64756
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64756 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64756
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.