| Publication Date: |
|
| Last Update: |
|
| Current Version: | V1.1 |
| CVSS v3.1 Base Score: | 9.8 |
| Affected Product and Versions | Remediation |
|---|---|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions < V1.8.0 affected by CVE-2025-15467 |
Update to V1.8.0 or later version
|
|
All versions < V3.3.2 affected by CVE-2025-15467 |
Update to V3.3.2 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is planned
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is planned
|
|
|
|
|
|
|
|
|
|
|
|
|
|
All versions >= V4.0.700 affected by CVE-2025-15467 |
Contact customer support
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is planned
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
|
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
|
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
|
|
|
All versions < V5.7 SP4 affected by CVE-2025-15467 |
Update to V5.7 SP4 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
|
|
|
|
|
|
All versions < V17 Update 9 affected by CVE-2025-15467 |
Update to V17 Update 9 or later version
|
|
All versions < V21 affected by CVE-2025-15467 |
Update to V21 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions >= V6.3 affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions >= V6.3 affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions >= V6.3 affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions >= V6.3 affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions >= V6.3 affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions < V1.0 SP2 Update 5 affected by CVE-2025-15467 |
Update to V1.0 SP2 Update 5 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions < V4.2 SP3 affected by CVE-2025-15467 |
Update to V4.2 SP3 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
|
All versions < V2.15.3.0 affected by CVE-2025-15467 |
Update to V2.15.3.0 or later version
|
|
All versions affected by CVE-2025-15467 |
Currently no fix is available
|
| Known Not Affected Products | Reason |
|---|---|
|
|
Show more details
|
|
|
Show more details
|
|
|
Show more details
|
|
|
Show more details
|
|
|
Show more details
|
Siemens has identified the following specific mitigations that customers can apply to reduce the risk:
Product-specific remediations or mitigations can be found in the section
Known Affected Products.
Please follow the General Security Recommendations.
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
This chapter describes all vulnerabilities (CVE-IDs) addressed in this security advisory. Wherever applicable, it also documents the product-specific impact of the individual vulnerabilities.
Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.
When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.
Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.
OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
| CVSS v3.1 Base Score | 9.8 |
| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-787: Out-of-bounds Write |
| V1.0 (2026-06-09): | Publication Date |
| V1.1 (2026-07-14): | Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT |