PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66382 Siemens CVE debrief

CVE-2025-66382 is a low-severity availability issue in libexpat that Siemens mapped to several SIMATIC S7-1500 CPU 1518 MFP/F MFP and SIPLUS variants. A crafted file of roughly 2 MiB can make processing take dozens of seconds, creating a denial-of-service-style slowdown rather than a confidentiality or integrity impact. CISA’s advisory lists no fix at the time of the source publication and recommends restricting access to the additional GNU/Linux subsystem shell and only running trusted applications.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
LOW 2.9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Operators and maintainers of Siemens SIMATIC S7-1500 CPU 1518-4/1518F-4 PN/DP MFP and SIPLUS variants, especially where the additional GNU/Linux subsystem is enabled or third-party software is deployed.

Technical summary

The supplied advisory text attributes the issue to libexpat through 2.7.3. On affected Siemens products, a specially crafted file of approximately 2 MiB can cause parsing/processing to consume dozens of seconds of CPU time. The CVSS vector (AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) matches a local, high-complexity, availability-only issue. Siemens/CISA list five affected product IDs and note that no fix is currently available.

Defensive priority

Medium for deployments that expose the additional GNU/Linux subsystem or accept untrusted files; low otherwise.

Recommended defensive actions

  • Limit access to the additional GNU/Linux subsystem shell to trusted personnel only.
  • Avoid processing untrusted or unexpected files on affected devices.
  • Only build and run applications from trusted sources.
  • Monitor affected systems for unusual CPU or task latency during file processing.
  • Track Siemens ProductCERT and CISA updates for any future fix or mitigation guidance.

Evidence notes

Source publication date is 2025-06-10, with the latest supplied update on 2026-05-14. The advisory text explicitly states: “In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.” The CSAF data maps the issue to Siemens SIMATIC S7-1500 CPU 1518-4/1518F-4 PN/DP MFP and SIPLUS variants and includes a remediation entry stating that no fix is available. The CVSS vector indicates local access, high attack complexity, and availability-only impact.

Official resources

CISA published ICSA-25-162-05 on 2025-06-10 and updated the republication through 2026-05-14. The underlying vendor source referenced by CISA is Siemens ProductCERT advisory SSA-082556.