CVE-2025-15467

HIGH

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. ...

Affects 1 product across 3 vendors.

BCS7.5
CVSS 3.18.8
EPSS47.6%
Percentile99th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

ABB AC500 V3 is vulnerable to a stack buffer overflow in the Cryptographic Message Syntax, which could lead to a crash, denial-of-service, or remote code execution.

BSID: BS-2026-GLOBAL-296613-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-15467?
ABB AC500 V3 is vulnerable to a stack buffer overflow in the Cryptographic Message Syntax, which could lead to a crash, denial-of-service, or remote code execution.
What is the CVSS score for CVE-2025-15467?
CVE-2025-15467 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. EPSS: 47.6%.
Is CVE-2025-15467 actively exploited?
No confirmed active exploitation of CVE-2025-15467 as of 2026-07-29.
How do I remediate CVE-2025-15467?
Priority: IMMEDIATE. Advisory: https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703 PSIRT: [email protected]
What systems are affected by CVE-2025-15467?
CVE-2025-15467 affects: Fortinet, Openssl, Siemens.
Vulnerability Details
CVE IDCVE-2025-15467
BSIDBS-2026-GLOBAL-296613-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published2026-07-28
Last Modified2026-07-28
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected: Des

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited through a malformed cryptographic message syntax input, which causes a buffer overflow in the affected software.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Fortinet —
Openssl Openssl
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashc2fd957fa34239a0e73c110240e3ade6071dea78a715730f2048cb96eea5d1f4619b2f8ed99aa1f4fb4635b57641cd6e0d170ca67876cdf3d1b3666edd06dc9d
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2022-35846 9.8 An improper restriction of excessive authentication attempts vulnerability [C... CVE-2021-24019 9.8 An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS... CVE-2023-34993 9.8 A improper neutralization of special elements used in an os command ('os comm...
View all Fortinet CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →