PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66031 Siemens CVE debrief

CVE-2025-66031 is a high-severity denial-of-service issue affecting Siemens SIDIS Prime versions earlier than 4.0.800. According to the advisory, an uncontrolled recursion condition in node-forge/ASN.1 parsing can be triggered by remote, unauthenticated attackers using deep DER structures, leading to stack exhaustion and service disruption.

Vendor
Siemens
Product
SIDIS Prime
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-12
Advisory published
2026-03-10
Advisory updated
2026-03-12

Who should care

Siemens SIDIS Prime operators, OT/ICS defenders, and any teams that accept or proxy untrusted DER/ASN.1 inputs in affected versions (<4.0.800).

Technical summary

The advisory describes a parser recursion flaw: crafted nested ASN.1/DER input can cause unbounded recursive parsing until the call stack is exhausted. The issue is network-reachable, requires no privileges or user interaction, and affects SIDIS Prime versions below 4.0.800; Siemens lists V4.0.800 or later as the fix.

Defensive priority

High. The issue is remotely triggerable without authentication and can disrupt exposed services by exhausting the stack. Prioritize patching on any system that processes untrusted DER/ASN.1 content.

Recommended defensive actions

  • Update Siemens SIDIS Prime to V4.0.800 or later.
  • Inventory all deployments and identify any versions below 4.0.800.
  • Restrict exposure of services that parse untrusted DER/ASN.1 data.
  • Monitor affected systems for repeated crashes, restarts, or stack-exhaustion symptoms.
  • Follow CISA ICS recommended practices for defense-in-depth and segmentation.

Evidence notes

CISA CSAF advisory ICSA-26-071-03 was published on 2026-03-10 and republished on 2026-03-12. The supplied source description states that deep ASN.1 structures can trigger unbounded recursive parsing and stack exhaustion, with a fix in node-forge 1.3.2. The Siemens product metadata maps the affected product as SIDIS Prime versions <4.0.800 and remediation to V4.0.800 or later. No KEV entry is provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66031 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66031

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66031 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66031

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.