CVE-2025-39756

MEDIUM

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...

Affects 2 products across 3 vendors.

BCS5.18
CVSS 3.15.5
EPSS0.2%
Percentile6th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-401: Memory Leak

Software does not release allocated memory after use, causing progressive consumption until failure.

◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could potentially lead to a compromise in availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.

BSID: BS-2026-GLOBAL-257534-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-39756?
The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could potentially lead to a compromise in availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.
What is the CVSS score for CVE-2025-39756?
CVE-2025-39756 has CVSS 5.5 (Medium). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. EPSS: 0.2%.
Is CVE-2025-39756 actively exploited?
No confirmed active exploitation of CVE-2025-39756 as of 2026-07-29.
How do I remediate CVE-2025-39756?
Priority: MEDIUM. Advisory: https://git.kernel.org/stable/c/04a2c4b4511d186b0fce685da21085a5d4acd370
What systems are affected by CVE-2025-39756?
CVE-2025-39756 affects: Debian, Linux, Siemens.
What NERC-CIP standard applies to CVE-2025-39756?
NERC CIP CIP-007 CIP-007-R2: This CVE could allow an attacker to compromise the availability of the SIMATIC CN 4100, which is a critical component in the control system. CIP-007-R2 requires the implementation of security controls to protect against unauthorized access and ensure the availability of critical assets.
What IEC 62443 requirement maps to CVE-2025-39756?
IEC 62443 SR 7.6: The vulnerabilities in the SIMATIC CN 4100 could be exploited to affect the availability and integrity of the control system. SR 7.6 requires the implementation of security measures to protect against such threats and ensure the reliable operation of the system.
Vulnerability Details
CVE IDCVE-2025-39756
BSIDBS-2026-GLOBAL-257534-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Published2026-07-28
Last Modified2026-07-28
ICS Relevance65%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerabilities are locally exploitable with low privileges and do not require user interaction. The primary risk is a high impact on availability, which could affect the operational continuity of the affected systems.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Debian Debian Linux
Linux Linux Kernel
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation to isolate the affected SIMATIC CN 4100 devices from other critical systems. Regularly monitor the network for any suspicious activity.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE could allow an attacker to compromise the availability of the SIMATIC CN 4100, which is a critical component in the control system. CIP-007-R2 requires the implementation of security controls to protect against unauthorized access and ensure the availability of critical assets.
IEC 62443: SR 7.6
The vulnerabilities in the SIMATIC CN 4100 could be exploited to affect the availability and integrity of the control system. SR 7.6 requires the implementation of security measures to protect against such threats and ensure the reliable operation of the system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashbcfa6aa740e4481db0e1274f993cf9855d760483e41b7a8c5d5a2df2094ba4b2788edb1f7040ebfe49063a04b06d18763ea7fe8a5576090247865e261ff8ff20
Related CVEs affecting Debian
CVE-1999-0698 10.0 Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. CVE-2001-0554 10.0 Buffer overflow in BSD-based telnetd telnet daemon on various operating syste... CVE-2000-0666 10.0 rpc.statd in the nfs-utils package in various Linux distributions does not pr... CVE-2003-0648 10.0 Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local use... CVE-2003-0098 10.0 Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allo...
View all Debian CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →