Junglewise Threat Intelligence

CVE-2025-40798: Siemens SIMATIC PCS neo out-of-bounds read in UMC

CVE-2025-40798 · Severity: high · CVSS 7.5 · Published 2025-09-09

Technologies: Siemens Simatic Pcs Neo, Siemens User Management Component. Vendors: Siemens.

Executive brief

Siemens SIMATIC PCS neo, a control system used in industrial plants, and its User Management Component (UMC) are affected by a security flaw. An attacker could remotely crash the system, leading to a denial-of-service condition that disrupts plant operations and user management services. This could prevent authorized personnel from accessing or managing critical industrial infrastructure.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the integrated User Management Component (UMC) used by Siemens SIMATIC PCS neo. The flaw is reachable over the network without authentication. By sending specially crafted packets to the affected component, an attacker can trigger an invalid memory read, leading to a crash of the service (Denial of Service). Siemens has released updates for UMC (V2.15.1.3) and SIMATIC PCS neo V6.0 (V6.0 SP1 Update 1) to address the issue. For versions where no fix is planned, Siemens recommends blocking TCP ports 4002 and 4004.

Affected products

  • Siemens SIMATIC PCS neo V4.1 (All versions), V5.0 (All versions), V6.0 (All versions < V6.0 SP1 Update 1)
  • Siemens User Management Component (UMC) All versions < V2.15.1.3

Timeline

  • 2025-09-09: disclosed: Initial publication of advisory SSA-722410
  • 2025-10-14: other: Advisory updated to include SIMATIC PCS neo V6.0 as affected
  • 2026-06-09: patched: Fix released for SIMATIC PCS neo V6.0

References

Related threats