ics-otregulatorNewsThe Broadside1 min read

Siemens ships CADRA V2511 while Foxit fixes remain open

The patch closes old library debt, but CISA's mitigation-only rows keep operators from treating V2511 as complete.


TL;DR

Siemens released CADRA V2511, and CISA lists it as the vendor fix for CADRA versions before V2511 affected by zlib CVEs including CVE-2016-9841, CVE-2022-37434 and CVE-2023-45853, each scored 9.8. Primes, subs and contractors using CADRA in chemical, commercial facilities, communications or energy environments should also keep the Foxit-related V8 items open, because CISA lists mitigation only for CVE-2025-10585 and CVE-2025-13223.

CISA's CADRA advisory is a patch ticket with an inventory lesson. Siemens released CADRA V2511, which CISA lists as the vendor fix for CADRA versions before V2511 affected by the older zlib issues, including three CVSS 9.8 CVEs tied to unauthenticated remote code execution or denial of service risk. For primes, subs and other contractors using CADRA in chemical, commercial facilities, communications or energy environments, the action is immediate: verify CADRA versions and move pre-V2511 deployments forward. The closure step needs a second look. CISA also lists two Foxit-related V8 vulnerabilities, CVE-2025-10585 and CVE-2025-13223, with mitigation only: block untrusted or external web content from sensitive systems. That means V2511 is necessary inventory work, while the mitigation-only rows still need an owner.


Published ·Deep Fathom