# Siemens patches OpenSSL flaw in industrial gear

Published: 2026-06-23 · Severity: high · Sectors: manufacturing, transportation, energy, healthcare, financial-services, government-national
Canonical: https://vorant.io/reports/bdd28d10-9fe7-5bc7-b3c3-2c1d95259612/siemens-patches-openssl-flaw-in-industrial-gear

> Siemens has released patches for CVE-2025-15467, a critical OpenSSL stack buffer overflow affecting over 100 industrial control system products that could enable remote code execution.

Siemens has published fixes for CVE-2025-15467, a stack-based buffer overflow in OpenSSL's parsing of CMS AuthEnvelopedData messages. The vulnerability affects OpenSSL versions 3.0 through 3.6 and allows an attacker to supply a crafted CMS message with an oversized initialization vector, triggering a stack-based out-of-bounds write before any authentication occurs. No valid key material is required to exploit the flaw.

The vulnerability impacts more than 100 Siemens industrial products, including the SCALANCE switch and router families, SIMATIC HMI panels, SIMATIC WinCC SCADA systems, RUGGEDCOM networking equipment, and various industrial software packages. Affected sectors include critical manufacturing, transportation, energy, healthcare, financial services, and government facilities. Siemens has released patches for products including SIMATIC STEP 7 V5, SIMATIC WinCC OA, SIMATIC HMI panels, SINEC INS, and the User Management Component.

For products where fixes are not yet available, Siemens recommends defense-in-depth measures including restricting access to untrusted CMS/PKCS#7 content, securing connected email servers with TLS/SSL, implementing IP allowlists, and following the company's operational guidelines for Industrial Security. Organizations are advised to update to the latest versions where available and apply network segmentation to protect vulnerable systems.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15467

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bdd28d10-9fe7-5bc7-b3c3-2c1d95259612/siemens-patches-openssl-flaw-in-industrial-gear.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
