Junglewise Threat Intelligence

CVE-2025-40795: Siemens SIMATIC PCS neo stack overflow in User Management Component

CVE-2025-40795 · Severity: critical · CVSS 9.8 · Published 2025-09-09

Technologies: Siemens Simatic Pcs Neo, Siemens User Management Component. Vendors: Siemens.

Executive brief

Siemens SIMATIC PCS neo is a control system used to manage industrial plants and infrastructure. A critical security flaw in its user management component could allow an unauthorized person to remotely take control of the system or shut it down entirely. This could lead to significant operational disruptions, loss of control over industrial processes, or unauthorized access to sensitive plant data.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Siemens User Management Component (UMC) integrated into SIMATIC PCS neo. The vulnerability can be triggered by an unauthenticated remote attacker over the network without any user interaction. Successful exploitation could lead to arbitrary code execution with high privileges or a complete denial of service of the management component. Siemens has released updates for UMC (V2.15.1.3) and PCS neo V6.0 (SP1 Update 1), though no fixes are currently planned for PCS neo V4.1 and V5.0. Mitigations include blocking TCP ports 4002 and 4004.

Affected products

  • Siemens SIMATIC PCS neo V4.1 (All versions), V5.0 (All versions), V6.0 < V6.0 SP1 Update 1
  • Siemens User Management Component (UMC) All versions < V2.15.1.3

Timeline

  • 2025-09-09: disclosed
  • 2025-09-09: advisory
  • 2026-06-09: patched: Fix released for SIMATIC PCS neo V6.0

References

Related threats