Junglewise Threat Intelligence

CVE-2025-40797: Siemens SIMATIC PCS neo out-of-bounds read in UMC

CVE-2025-40797 · Severity: high · CVSS 7.5 · Published 2025-09-09

Technologies: Siemens Simatic Pcs Neo, Siemens User Management Component. Vendors: Siemens.

Executive brief

Siemens SIMATIC PCS neo, a control system used for industrial plant management, contains a vulnerability in its user management component. An unauthenticated attacker could remotely exploit this flaw to crash the system, leading to a denial-of-service condition. This could disrupt plant operations and maintenance activities until the service is restored.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Siemens User Management Component (UMC) integrated into SIMATIC PCS neo. The flaw is triggered when the component processes specially crafted input, allowing an unauthenticated remote attacker to access memory outside of intended buffers. This memory corruption leads to a denial-of-service (DoS) condition by crashing the affected service. The vulnerability affects SIMATIC PCS neo versions 4.1, 5.0, and 6.0 (prior to SP1 Update 1), as well as standalone UMC versions prior to V2.15.1.3. Siemens recommends updating to the latest versions or blocking TCP ports 4002 and 4004 as a mitigation.

Affected products

  • Siemens SIMATIC PCS neo V4.1 (All versions), V5.0 (All versions), V6.0 (All versions < V6.0 SP1 Update 1)
  • Siemens User Management Component (UMC) All versions < V2.15.1.3

Timeline

  • 2025-09-09: disclosed: Initial publication of SSA-722410
  • 2025-09-09: advisory
  • 2026-06-09: patched: Fix released for SIMATIC PCS neo V6.0 via SP1 Update 1

References

Related threats