CVE-2025-39691
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...
Affects 2 products across 3 vendors.
Software references memory after it has been freed, leading to corruption, crashes, or code execution.
The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could compromise availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.
BSID: BS-2026-GLOBAL-257456-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-39691?
What is the CVSS score for CVE-2025-39691?
Is CVE-2025-39691 actively exploited?
How do I remediate CVE-2025-39691?
What systems are affected by CVE-2025-39691?
What NERC-CIP standard applies to CVE-2025-39691?
What IEC 62443 requirement maps to CVE-2025-39691?
| CVE ID | CVE-2025-39691 |
|---|---|
| BSID | BS-2026-GLOBAL-257456-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-07-28 |
| Last Modified | 2026-07-28 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6
Source: NIST NVD / MITRE CVE Database
The vulnerabilities are locally exploitable with low privileges and do not require user interaction. Successful exploitation could lead to a compromise of the system's availability, integrity, and confidentiality.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Debian | Debian Linux | — |
| Linux | Linux Kernel | — |
| Siemens | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation to isolate the SIMATIC CN 4100 from other critical systems and monitor traffic for suspicious activity.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE could allow an attacker to compromise the availability and integrity of the control system, which violates the requirement for maintaining the security of critical cyber assets.
The vulnerabilities could allow an attacker to bypass security controls and compromise the system, which is a violation of the security requirements for protecting against unauthorized access and manipulation.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 9b43e6c636e02ea3b9156fbca632f0635742fac50bd06462dae433d90ba9005164530422a1a3b63ed88ee075b26f684172537fe687ea1e11314113ba806cd2d9 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →