CVE-2025-40743

8.3

Siemens · SINUMERIK

Siemens SINUMERIK devices contain an authentication bypass vulnerability in the VNC access service, allowing unauthenticated attackers to gain unauthorized remote access to the system.

Executive summary

An authentication bypass vulnerability in the VNC service of Siemens SINUMERIK industrial controllers poses a high risk to system confidentiality and integrity.

Vulnerability

This vulnerability, classified as CWE-288, involves improper validation of authentication for the VNC access service. An unauthenticated attacker can leverage this alternate path to gain unauthorized remote access to the affected industrial controllers.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating a high level of severity. Successful exploitation could lead to unauthorized control over critical industrial equipment, resulting in potential disruption of manufacturing processes, loss of system availability, and compromise of sensitive operational data.

Remediation

Immediate Action: Update the affected SINUMERIK firmware to the specified patched versions provided in the Siemens security advisory SSA-177847.

Proactive Monitoring: Monitor network traffic for unauthorized attempts to access VNC ports (typically TCP 5900) on industrial control systems and review system access logs for anomalous login activity.

Compensating Controls: Restrict access to the VNC service by implementing network segmentation or firewall rules that limit connectivity to authorized management workstations only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of industrial control environments, organizations should prioritize patching these Siemens SINUMERIK devices. If immediate updates are not feasible, network-level restrictions on the VNC service are essential to prevent unauthorized access until the firmware can be upgraded.

More Siemens CVEs

Sources