PatchSiren cyber security CVE debrief
CVE-2025-9232 Siemens CVE debrief
CVE-2025-9232 describes a crash-only out-of-bounds read in OpenSSL’s HTTP client path when no_proxy is set and the URL authority host is an IPv6 address. The practical impact is denial of service for applications that pass attacker-influenced URLs into the OpenSSL HTTP client APIs. The source advisory also notes that OCSP and CMP client code paths use the same HTTP client functionality, but their URLs are unlikely to be attacker-controlled. The advisory was published on 2026-05-12 and republished/modified on 2026-05-14.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Administrators and developers who use affected Siemens SIMATIC CN 4100 deployments, and application teams that call OpenSSL HTTP client APIs with externally influenced URLs. Also review OCSP or CMP client use if those flows rely on the same HTTP client behavior.
Technical summary
The issue is an out-of-bounds read in OpenSSL’s HTTP client API functions. It is triggered only when the no_proxy environment variable is set and the URL host portion is an IPv6 address. The advisory states the read can lead only to a crash, so the impact is denial of service rather than confidentiality or integrity compromise. The vulnerable code was introduced in patch releases 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0, and 3.5.0. The advisory also states that the FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected because the HTTP client implementation is outside the FIPS boundary.
Defensive priority
Medium, with higher priority for environments where application code passes untrusted or externally influenced HTTP URLs into OpenSSL and systems commonly use no_proxy. Priority is lower when URL inputs are fully controlled and isolated.
Recommended defensive actions
- Update affected Siemens SIMATIC CN 4100 systems to V5.0 or later, per the vendor remediation.
- Review application code that uses OpenSSL HTTP client APIs to confirm whether URLs can be influenced by users or upstream systems.
- Check whether no_proxy is set in the runtime environment for affected services and document where it is required.
- If OCSP or CMP clients are used, verify their HTTP handling paths and confirm whether they inherit the same runtime conditions.
- Use the supplied CISA and Siemens advisories as the source of truth for affected product/version scope before scheduling maintenance.
Evidence notes
The source advisory text states that an OpenSSL HTTP client API path may trigger an out-of-bounds read when no_proxy is set and the host is an IPv6 address, and that the result is a crash leading to denial of service. It also states the issue was assessed as low severity because exploitation requires an attacker-controlled URL and the crash-only outcome. The supplied source metadata maps the advisory to Siemens SIMATIC CN 4100 < 5.0 and cites remediation to update to V5.0 or later. CISA’s CSAF record was published 2026-05-12 and republished 2026-05-14.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-9232 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-9232
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-9232 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9232
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.