Siemens CADRA multiple zlib and Chrome vulnerabilities
Siemens CADRA versions below V2511 are affected by multiple zlib and Chromium V8 vulnerabilities; update to V2511 or later to remediate.
Siemens CADRA is affected by a set of legacy and recent vulnerabilities spanning zlib compression library flaws and Google Chrome V8 type confusion issues. The zlib vulnerabilities (CVE-2005-2096, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2017-14919, CVE-2018-25032, CVE-2022-37434, CVE-2023-45853, CVE-2026-22184) range from denial-of-service to buffer overflow and heap corruption conditions, with some requiring specific application-level triggers. The more recent Chromium V8 issues (CVE-2025-10585, CVE-2025-13223) present type confusion leading to heap corruption via crafted HTML and are currently unpatched. CADRA versions prior to V2511 are known affected; V2511 or later addresses the zlib issues. For the two unfixed Chrome vulnerabilities, Siemens recommends blocking access to untrusted or external web content. Organizations running CADRA in critical infrastructure environments (chemical, energy, communications) should prioritize updates and network segmentation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free