← All Advisories

CVE-2026-43025

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-43025

Key Details

CVECVE-2026-43025
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ctnetlink: ignore explicit helper on new expectations

Use the existing master conntrack helper, anything else is not really

supported and it just makes validation more complicated, so just ignore

what helper userspace suggests for this expectation.

This was uncovered when validating CTA_EXPECT_CLASS via different helper

provided by userspace than the existing master conntrack helper:

BUG: KASAN: slab-out-of-bounds in nf_ct_expect_related_report+0x2479/0x27c0

Read of size 4 at addr ffff8880043fe408 by task poc/102

Call Trace:

nf_ct_expect_related_report+0x2479/0x27c0

ctnetlink_create_expect+0x22b/0x3b0

ctnetlink_new_expect+0x4bd/0x5c0

nfnetlink_rcv_msg+0x67a/0x950

netlink_rcv_skb+0x120/0x350

Allowing to read kernel memory bytes off the expectation boundary.

CTA_EXPECT_HELP_NAME is still used to offer the helper name to userspace

via netlink dump. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-43025
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-43025