Code Execution Vulnerability in SIMATIC S7-PLCSIM and Related Siemens Products
CVE-2025-40759
8.5HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2025-40759?
A critical vulnerability has been detected in various Siemens products, including SIMATIC S7-PLCSIM and SIMATIC STEP 7, which fails to properly sanitize security properties stored within project files. This oversight may allow an attacker to exploit type confusion, leading to the potential execution of arbitrary code within the affected applications. Organizations using these products should assess their installation for any impacted versions and take necessary measures to mitigate risks.
Affected Version(s)
SIMATIC S7-PLCSIM V17 0
SIMATIC STEP 7 V17 0
SIMATIC STEP 7 V18 0