CVE-2025-31115

N/A

View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could caus...

Affects 0 products across 2 vendors.

BCS4.26
CVSS v48.7
EPSS0.6%
Percentile47th
PatchUnknown
CWE Weakness Definitions
CWE-366: CWE-366
CWE-416: Use After Free

Software references memory after it has been freed, leading to corruption, crashes, or code execution.

CWE-476: NULL Pointer Dereference

Software attempts to use a NULL pointer, causing a crash and denial of service.

CWE-826: CWE-826
Related Attack Patterns (CAPEC)
CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions
via CWE-366
CAPEC-26 Leveraging Race Conditions
via CWE-366

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the multithreaded .xz decoder in liblzma of XZ Utils versions 5.3.3alpha to 5.8.0 can lead to a crash and potentially more severe issues such as heap use after free and null pointer dereference.

BSID: BS-2025-GLOBAL-270914-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-31115?
A vulnerability in the multithreaded .xz decoder in liblzma of XZ Utils versions 5.3.3alpha to 5.8.0 can lead to a crash and potentially more severe issues such as heap use after free and null pointer dereference.
Is CVE-2025-31115 actively exploited?
No confirmed active exploitation of CVE-2025-31115 as of 2026-07-01.
How do I remediate CVE-2025-31115?
Priority: HIGH.
What systems are affected by CVE-2025-31115?
CVE-2025-31115 affects: Fujitsu-Siemens, Siemens.
Vulnerability Details
CVE IDCVE-2025-31115
BSIDBS-2025-GLOBAL-270914-I BreachSpider Global ID
Published2026-06-30
Last Modified2026-06-30
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data. The following versions of XZ Utils vulnerability impacting B&R Products are affected: PPC3100 <1.8.1, 1.8.1 (CVE-2025-31115) C50 <1.8.0, 1.8.0 (CVE-2025-31115) C80 <1.8.0, 1.8.0 (CVE-2025-31115) FT50 <1.8.1, 1.8.1 (CVE-2025-31115) MT50 <1.8.1, 1.8.1 (CVE-20

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by invalid input to the lzma_stream_decoder_mt function, which can be exploited by providing specially crafted .xz files to applications or libraries using this function.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens &mdash;
Siemens &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 25 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →