Junglewise Threat Intelligence

CVE-2025-40796: Siemens SIMATIC PCS neo out-of-bounds read in UMC

CVE-2025-40796 · Severity: high · CVSS 7.5 · Published 2025-09-09

Technologies: Siemens Simatic Pcs Neo, Siemens User Management Component. Vendors: Siemens.

Executive brief

Siemens SIMATIC PCS neo, a control system used for plant automation, and its User Management Component (UMC) are affected by a security flaw. An attacker could remotely crash the system, leading to a denial-of-service condition that disrupts plant operations and user management services. This could prevent authorized personnel from accessing or managing critical industrial infrastructure.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Siemens User Management Component (UMC) integrated into SIMATIC PCS neo. The flaw is triggered when the component processes specially crafted input, allowing an unauthenticated remote attacker to access memory outside of intended buffers. This memory corruption leads to a crash of the UMC service, resulting in a denial-of-service (DoS) condition. The vulnerability can be exploited over the network via TCP ports 4002 and 4004. Siemens has released updates for PCS neo V6.0 and standalone UMC; however, no fixes are currently planned for PCS neo V4.1 and V5.0, where mitigations like port blocking are recommended.

Affected products

  • Siemens SIMATIC PCS neo V4.1 (All versions), V5.0 (All versions), V6.0 (All versions < V6.0 SP1 Update 1)
  • Siemens User Management Component (UMC) All versions < V2.15.1.3

Timeline

  • 2025-09-09: disclosed: Initial publication of advisory SSA-722410
  • 2025-10-14: other: Advisory updated to include SIMATIC PCS neo V6.0 as affected
  • 2026-06-09: patched: Fix released for SIMATIC PCS neo V6.0

References

Related threats