CVE-2025-31115
View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could caus...
Affects 0 products across 2 vendors.
Software references memory after it has been freed, leading to corruption, crashes, or code execution.
Software attempts to use a NULL pointer, causing a crash and denial of service.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability in the multithreaded .xz decoder in liblzma of XZ Utils versions 5.3.3alpha to 5.8.0 can lead to a crash and potentially more severe issues such as heap use after free and null pointer dereference.
BSID: BS-2025-GLOBAL-270914-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-31115?
Is CVE-2025-31115 actively exploited?
How do I remediate CVE-2025-31115?
What systems are affected by CVE-2025-31115?
| CVE ID | CVE-2025-31115 |
|---|---|
| BSID | BS-2025-GLOBAL-270914-I BreachSpider Global ID |
| Published | 2026-06-30 |
| Last Modified | 2026-06-30 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data. The following versions of XZ Utils vulnerability impacting B&R Products are affected: PPC3100 <1.8.1, 1.8.1 (CVE-2025-31115) C50 <1.8.0, 1.8.0 (CVE-2025-31115) C80 <1.8.0, 1.8.0 (CVE-2025-31115) FT50 <1.8.1, 1.8.1 (CVE-2025-31115) MT50 <1.8.1, 1.8.1 (CVE-20
Source: NIST NVD / MITRE CVE Database
The vulnerability is triggered by invalid input to the lzma_stream_decoder_mt function, which can be exploited by providing specially crafted .xz files to applications or libraries using this function.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →