Executive Summary

CVE-2025-39691 is a local privilege escalation class defect residing in the additional GNU/Linux subsystem shipped in firmware V3.1.6 of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP, including the SIPLUS hardened variant. Because the MFP (Multifunctional Platform) hosts a Linux runtime on the same physical device that executes safety-rated F control logic, a compromise of the Linux side sits one boundary away from processes that govern physical plant state.

Technical Exposure Breakdown

The affected asset is not a conventional PLC. The 1518-4 PN/DP MFP (order number 6ES7518-4AX00-1AB0, versions at or above V3.1.6) is a hybrid controller. It runs standard STEP 7 control code alongside a separate GNU/Linux subsystem intended for high-level applications written in C/C++ or hosted through the ODK and container tooling. That Linux subsystem is where CVE-2025-39691 lives, carrying a CVSS base score of 7.8 with a local vector.

A CVSS 7.8 with a local attack vector means an actor already holds low-privilege execution inside the Linux runtime and uses the defect to escalate. This is not a remote, pre-authentication network worm. The realistic path is a supply chain application, a compromised container, a malicious or trojanized high-level app deployed to the MFP subsystem, or an operator with legitimate low-privilege shell access who pivots upward.

The material risk is the shared silicon. The Linux subsystem and the F (fail-safe) control runtime coexist on one CPU module. Siemens architects a separation boundary between the two, but privilege escalation inside Linux increases the pressure on that boundary and expands the toolset available to an attacker seeking to influence I/O, engineering access, or diagnostic channels. Treat any elevated foothold on the MFP as adjacent to the safety instrumented function, not isolated from it.

OT Impact and Compliance Risk

Physically, the concern is any deployment where the 1518-4 MFP drives fail-safe functions. If the Linux side is subverted and used to interfere with logic execution, engineering downloads, or communications timing, the failure mode ranges from unexpected safety trips and production loss to degraded protection of the physical process the F logic is meant to guard.

Under IEC 62443, this maps directly to zone and conduit segmentation requirements and to secure development lifecycle expectations for the hosted application environment (62443-4-1 and 4-2). For NERC CIP registered entities, an MFP running Linux applications in a medium or high impact BES Cyber System expands the CIP-007 patch management and CIP-010 configuration baseline scope, because the Linux subsystem is now a patchable, configurable software surface that most asset inventories were never built to track. Water and wastewater operators under AWIA 2018, and pipeline operators under TSA SD-02C, should treat the MFP Linux runtime as a distinct asset class in their risk assessments rather than folding it into generic PLC counts.

Compensating Controls

Do not rely on a firmware update alone, and do not attempt active vulnerability scanning against these controllers. Scan traffic and aggressive probing can stall or brick industrial CPUs, and the MFP is not an exception. Apply these controls first:

Passive observation is mandatory here. The Linux subsystem changes the asset from a deterministic PLC into a general purpose compute node with a control safety function attached, and it must be governed accordingly.

BreachSpider Intel

BreachSpider tracks CVE-2025-39691 and the broader SIMATIC MFP exposure surface across 25,000+ ICS CVEs, providing continuous monitoring so OT teams see fix availability and active exploitation signals before they reach the plant floor.