CVE-2025-40797
7.5Siemens · SIMATIC PCS neo and User Management Component (UMC)
An out-of-bounds read vulnerability in the Siemens SIMATIC PCS neo UMC component allows an unauthenticated remote attacker to trigger a denial of service condition.
Executive summary
An out-of-bounds read vulnerability in Siemens SIMATIC PCS neo and its User Management Component enables unauthenticated remote attackers to cause a denial of service.
Vulnerability
The software contains an out-of-bounds read vulnerability within the integrated User Management Component, which can be exploited by an unauthenticated remote attacker to crash the service.
Business impact
The exploitation of this vulnerability results in a denial of service, which can cause significant operational disruption in industrial control environments. Given the CVSS score of 7.5, this high-severity flaw threatens system availability and could hinder critical process management functions provided by the SIMATIC PCS neo platform.
Remediation
Immediate Action: Update SIMATIC PCS neo to V6.0 SP1 Update 1 or later and update the User Management Component to version 2.15.1.3 or later as specified by the vendor.
Proactive Monitoring: Monitor system logs for unexpected service restarts, crashes, or abnormal memory usage patterns in the UMC process.
Compensating Controls: Restrict network access to the UMC interface by implementing strict firewall rules to allow only authorized traffic from trusted management segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the potential for remote denial of service, organizations utilizing Siemens SIMATIC PCS neo must prioritize patching the UMC component. Administrators should verify their current version numbers against the affected range and coordinate an orderly update process to restore service stability and security.