PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-69420 Siemens CVE debrief

A type confusion vulnerability in OpenSSL's TimeStamp Response verification code affects the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The flaw occurs in `TS_RESP_verify_response()` where `ossl_ess_get_signing_cert()` and `ossl_ess_get_signing_cert_v2()` access signing certificate attribute values without validating the ASN.1 type. When processing a malformed TimeStamp Response with a type other than `V_ASN1_SEQUENCE`, the code dereferences invalid memory through the `ASN1_TYPE` union, causing a crash. Exploitation requires an attacker to supply a malformed RFC 3161 TimeStamp Response to an application performing verification. The protocol's limited adoption and the Denial of Service-only impact resulted in a Low severity assessment, though the CVSS vector indicates HIGH severity (7.5). OpenSSL FIPS modules (3.5, 3.4, 3.3, 3.0) are unaffected as the TimeStamp implementation falls outside the FIPS boundary. Affected OpenSSL versions include 3.6, 3.5, 3.4, 3.3, 3.0, and 1.1.1; version 1.0.2 is not affected.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Organizations operating Siemens SIMATIC S7-1500 TM MFP systems with active GNU/Linux subsystems, particularly those utilizing TimeStamp Response verification in industrial automation, PKI infrastructure, or code signing workflows. Security teams in OT/ICS environments should prioritize access controls given the absence of available patches.

Technical summary

The vulnerability stems from improper type validation in OpenSSL's ESS (Enhanced Security Services) signing certificate extraction functions. When `ossl_ess_get_signing_cert()` or `ossl_ess_get_signing_cert_v2()` processes a TimeStamp Response, they retrieve the signing certificate attribute value via `X509_ATTRIBUTE_get0_data()` without verifying that the returned `ASN1_TYPE` contains a `V_ASN1_SEQUENCE`. The `ASN1_TYPE` union contains multiple member types of varying sizes; accessing the `sequence` member when the actual type differs causes memory misinterpretation and invalid pointer dereference. This manifests as a NULL or invalid pointer read during `TS_RESP_verify_response()` execution. The crash occurs in the reading phase, not writing, limiting impact to availability loss. The FIPS module boundary exclusion is significant for compliance-sensitive deployments.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
  • Build and run only applications from trusted sources
  • Monitor for future Siemens security advisories regarding patch availability
  • Review application dependencies for OpenSSL TimeStamp Response functionality
  • Assess network segmentation to limit exposure of TimeStamp verification services

Evidence notes

The source advisory (ICSA-24-102-01) was initially published on 2024-04-09 and has undergone nine revision cycles through 2025-09-09, with CVE-2025-69420 added in a subsequent release. The advisory identifies the affected product as the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP, which incorporates vulnerable OpenSSL components. Siemens has published parallel guidance in SSA-265688. No patch is currently available per the source remediation data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-69420 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-69420

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-69420 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-69420

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.