Siemens CADRA

Summary

Siemens CADRA software versions prior to V2511 are affected by multiple vulnerabilities in zlib and Foxit. These vulnerabilities, including Improper Input Validation and buffer overflows, could allow remote attackers to cause denial of service. Siemens has released an update and recommends specific countermeasures.

IFF Assessment

FOE

This article details critical vulnerabilities in industrial software, posing a significant risk to operational technology environments.

Severity

9.8 Critical

The CVSS score of 9.8 indicates a critical severity, reflecting the potential for remote exploitation without authentication, leading to a complete loss of availability and integrity.

CISA KEV: Listed as actively exploited. Federal patch due: October 14, 2025. Known ransomware use: Unknown.

Defender Context

This alert highlights critical vulnerabilities in Siemens CADRA, impacting industrial control systems. Defenders should prioritize patching or implementing compensating controls for affected versions to mitigate risks of denial of service and potential further compromise.

Read Full Story →