Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0187

Published Jun 10, 2025·Last modified Jun 10, 2025
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als RUGGEDCOM, SCALANCE, SIMATIC en Tecnomatix

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (root/admin rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Toegang tot gevoelige gegevens
  • Spoofing

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-395

Use of NullPointerException Catch to Detect NULL Pointer Dereference

CWE-332

Insufficient Entropy in PRNG

CWE-940

Improper Verification of Source of a Communication Channel

CWE-466

Return of Pointer Value Outside of Expected Range

CWE-390

Detection of Error Condition Without Action

CWE-826

Premature Release of Resource During Expected Lifetime

CWE-222

Truncation of Security-relevant Information

CWE-310

CWE-310

CWE-273

Improper Check for Dropped Privileges

CWE-364

Signal Handler Race Condition

CWE-911

Improper Update of Reference Count

CWE-131

Incorrect Calculation of Buffer Size

CWE-304

Missing Critical Step in Authentication

CWE-684

Incorrect Provision of Specified Functionality

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-268

Privilege Chaining

CWE-366

Race Condition within a Thread

CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-407

Inefficient Algorithmic Complexity

CWE-371

CWE-371

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-667

Improper Locking

CWE-311

Missing Encryption of Sensitive Data

CWE-703

Improper Check or Handling of Exceptional Conditions

CWE-908

Use of Uninitialized Resource

CWE-617

Reachable Assertion

CWE-129

Improper Validation of Array Index

CWE-124

Buffer Underwrite ('Buffer Underflow')

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

CWE-345

Insufficient Verification of Data Authenticity

CWE-354

Improper Validation of Integrity Check Value

CWE-325

Missing Cryptographic Step

CWE-190

Integer Overflow or Wraparound

CWE-290

Authentication Bypass by Spoofing

CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

CWE-665

Improper Initialization

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-125

Out-of-bounds Read

CWE-404

Improper Resource Shutdown or Release

CWE-284

Improper Access Control

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-416

Use After Free

CWE-476

NULL Pointer Dereference

CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-611

Improper Restriction of XML External Entity Reference

CWE-787

Out-of-bounds Write

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-122

Heap-based Buffer Overflow

CWE-121

Stack-based Buffer Overflow

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-73

External Control of File Name or Path

CWE-20

Improper Input Validation

CWE-863

Incorrect Authorization

CWE-276

Incorrect Default Permissions

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard