PatchSiren cyber security CVE debrief
CVE-2025-6965 Siemens CVE debrief
CVE-2025-6965 is a high-severity issue mapped in CISA's Siemens SIDIS Prime advisory for versions before 4.0.800. The advisory text says SQLite versions before 3.50.2 can reach a condition where aggregate terms exceed the available columns, which may lead to memory corruption. The recommended fix is to upgrade to V4.0.800 or later.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-03-12
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-03-12
Who should care
Asset owners, operators, and integrators running Siemens SIDIS Prime below 4.0.800 should treat this as a priority patch. OT/ICS security teams and administrators responsible for systems that depend on the affected SIDIS Prime release should also review exposure and update plans.
Technical summary
CISA's CSAF advisory ICSA-26-071-03 maps CVE-2025-6965 to Siemens SIDIS Prime vers:intdot/<4.0.800. The source description states that SQLite versions before 3.50.2 can encounter a memory-corruption condition when the number of aggregate terms exceeds the number of columns available. The advisory lists CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L with a score of 7.7.
Defensive priority
High
Recommended defensive actions
- Inventory Siemens SIDIS Prime deployments and confirm whether any instance is below version 4.0.800.
- Upgrade affected systems to V4.0.800 or later, following Siemens maintenance procedures.
- Test the update on a representative system before broad deployment to avoid operational disruption.
- Limit unnecessary network exposure and restrict administrative access to SIDIS Prime systems where possible.
- Monitor affected hosts for crashes, instability, or other anomalous behavior until remediation is complete.
Evidence notes
Primary evidence comes from CISA's republished CSAF advisory ICSA-26-071-03, published 2026-03-10 and updated 2026-03-12 from Siemens ProductCERT advisory SSA-485750. The source corpus ties the CVE to Siemens SIDIS Prime versions below 4.0.800 and recommends upgrading to V4.0.800 or later. The advisory description also includes the SQLite aggregate-term memory-corruption condition and the listed CVSS vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-6965 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-6965
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-6965 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-6965
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.