PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25570 Siemens CVE debrief

Siemens SICAM SIAPP SDK contains a stack overflow condition caused by missing checks on input values. According to the public advisory, the issue can lead to code execution or denial of service. Siemens recommends updating to V2.1.7 or later, and the advisory was republished by CISA as ICSA-26-076-04.

Vendor
Siemens
Product
SICAM SIAPP SDK
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-17
Advisory published
2026-03-10
Advisory updated
2026-03-17

Who should care

Siemens customers, system integrators, and developers who use or embed the SICAM SIAPP SDK in industrial or control-system software should prioritize this issue.

Technical summary

The advisory scope identifies Siemens SICAM SIAPP SDK versions before V2.1.7 as affected (vers:intdot/<2.1.7). The flaw is described as missing input validation that can result in a stack overflow, with the supplied reference to CWE-121. CISA lists CVSS v3.1 as AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, which indicates potentially severe impact if an attacker can reach the vulnerable code path, but with local access and high attack complexity.

Defensive priority

High. Patch any affected deployments promptly, especially where the SDK is incorporated into operational or safety-critical software. Inventory downstream products that bundle the SDK and move them to V2.1.7 or later.

Recommended defensive actions

  • Identify all products, builds, and devices that include Siemens SICAM SIAPP SDK and confirm whether they are below V2.1.7.
  • Apply the vendor fix and update to V2.1.7 or later, then rebuild and redeploy any software that embeds the SDK.
  • Validate exposure against Siemens ProductCERT SSA-903736 and CISA ICSA-26-076-04, including any downstream packages or OEM integrations.
  • Use industrial-control-system defense-in-depth practices and increase monitoring on systems that cannot be patched immediately.

Evidence notes

The supplied CISA CSAF source item for ICSA-26-076-04 names Siemens SICAM SIAPP SDK vers:intdot/<2.1.7 as the affected product, states that unchecked input values can cause a stack overflow, and says this may enable code execution and denial of service. The same source item includes the remediation to update to V2.1.7 or later and provides CVSS v3.1 AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The source metadata also records that CISA republished Siemens ProductCERT advisory SSA-903736 on 2026-03-17 after the initial publication date of 2026-03-10.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25570 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25570

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25570 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25570

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-903736.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.