CVE-2025-40796

7.5

Siemens · SIMATIC PCS neo and User Management Component (UMC)

An out-of-bounds read vulnerability in the Siemens SIMATIC PCS neo User Management Component allows an unauthenticated remote attacker to cause a denial of service.

Executive summary

An unauthenticated remote attacker can trigger a denial of service condition in Siemens SIMATIC PCS neo and UMC due to an out-of-bounds read vulnerability.

Vulnerability

This flaw is an out-of-bounds read (CWE-125) residing within the integrated User Management Component. The vulnerability is exploitable by an unauthenticated remote attacker with no user interaction required.

Business impact

The ability for an unauthenticated attacker to remotely trigger a denial of service condition poses a significant risk to industrial control environments. Given the CVSS 4.0 score of 7.5, this vulnerability could result in unplanned downtime of critical automation systems, leading to operational disruption and potential safety concerns in manufacturing or utility sectors.

Remediation

Immediate Action: Update SIMATIC PCS neo to version V6.0 SP1 Update 1 and the User Management Component (UMC) to version V2.15.1.3 or later as specified in the official Siemens security advisory.

Proactive Monitoring: Monitor system logs for unexpected service restarts or performance degradation within the UMC component, which may indicate attempted exploitation.

Compensating Controls: Restrict network access to the management interfaces of the affected Siemens products using firewalls or industrial security appliances to ensure only authorized traffic can reach the UMC.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, particularly for organizations operating critical infrastructure. Administrators should prioritize the deployment of the provided Siemens patches to eliminate the risk of remote service disruption. If patching is not immediately feasible, network segmentation remains a vital secondary defense to block unauthorized access to the vulnerable component.

More Siemens CVEs

Sources