CVE-2025-40759

7.8

Siemens · SIMATIC, SIMOCODE ES, SIMOTION SCOUT TIA, SINAMICS Startdrive, SIRIUS Safety ES, SIRIUS Soft Starter ES

A deserialization of untrusted data vulnerability exists in various Siemens industrial software products, potentially allowing local attackers to achieve arbitrary code execution via user interaction.

Executive summary

A critical deserialization vulnerability in multiple Siemens industrial software products could allow an attacker with local access to achieve full system compromise.

Vulnerability

The software is susceptible to CWE-502: Deserialization of Untrusted Data. This flaw allows an attacker to execute arbitrary code by supplying a malicious serialized object, requiring a local user to interact with the application.

Business impact

Successful exploitation of this vulnerability results in total impact to confidentiality, integrity, and availability of the affected host system. Given the CVSS score of 7.8, this represents a high-severity risk to industrial control environments where these engineering tools are deployed, potentially leading to unauthorized system control or disruption of critical manufacturing processes.

Remediation

Immediate Action: Update the affected Siemens software suites to the versions specified in the vendor security advisory, specifically applying the latest updates (such as V17 Update 9, V19 Update 4, or V20 Update 4) as appropriate.

Proactive Monitoring: Monitor for unusual application crashes, unexpected background process creation, or anomalous file system modifications on engineering workstations.

Compensating Controls: Restrict access to engineering workstations to authorized personnel only and ensure that untrusted project files or data inputs are not processed by the affected applications.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing the affected Siemens TIA Portal ecosystem must prioritize the application of the vendor-provided updates. Due to the high potential impact on industrial operations, verify the versioning of all installed Siemens software packages and apply the relevant patches to eliminate the deserialization risk.

More Siemens CVEs

Sources