PatchSiren cyber security CVE debrief
CVE-2026-28389 Siemens CVE debrief
CVE-2026-28389 is a HIGH-severity denial-of-service vulnerability involving CMS EnvelopedData processing with KeyAgreeRecipientInfo. A crafted message can trigger a NULL pointer dereference when the optional parameters field of KeyEncryptionAlgorithmIdentifier is missing, which can crash affected software before authentication or cryptographic operations complete. The source advisory ties remediation to Siemens SIMATIC CN 4100 versions before 5.0 and notes that OpenSSL FIPS modules are not affected because the impacted code is outside the FIPS boundary.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Siemens SIMATIC CN 4100 operators and maintainers, especially where systems process untrusted CMS or S/MIME content. Security teams responsible for software that calls CMS_decrypt() on attacker-controlled input should also review exposure and patch status.
Technical summary
The issue occurs during processing of a CMS EnvelopedData message using KeyAgreeRecipientInfo. The code examines the optional parameters field of KeyEncryptionAlgorithmIdentifier without checking whether it is present, leading to a NULL pointer dereference if the field is missing. The result is a crash/denial of service, not a confidentiality or integrity impact. The advisory states that OpenSSL FIPS modules in 3.6, 3.5, 3.4, 3.3, and 3.0 are not affected because the vulnerable code lies outside the FIPS module boundary.
Defensive priority
High
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V5.0 or later.
- Identify any paths that process untrusted CMS EnvelopedData or S/MIME content and confirm whether CMS_decrypt() is reachable from attacker-controlled input.
- Limit or pre-validate untrusted CMS content before it reaches the affected parsing path, where operationally feasible.
- Review restart/crash monitoring for services that handle CMS data so a denial-of-service event is detected quickly.
- Use the official Siemens and CISA advisories to confirm product/version scope before scheduling remediation.
Evidence notes
This debrief is based on the CISA CSAF republication of Siemens ProductCERT advisory SSA-032379 for CVE-2026-28389. The source advisory was published on 2026-05-12 and republished/modified on 2026-05-14. The advisory explicitly describes a NULL pointer dereference in CMS EnvelopedData processing, a CVSS 3.1 score of 7.5 (HIGH), and remediation to V5.0 or later. It also states that the affected code is outside the OpenSSL FIPS module boundary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28389 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28389
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28389 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28389
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.