Code Execution Vulnerability in SIMATIC S7-PLCSIM and Related Siemens Products
CVE-2025-40759

8.5HIGH

What is CVE-2025-40759?

A critical vulnerability has been detected in various Siemens products, including SIMATIC S7-PLCSIM and SIMATIC STEP 7, which fails to properly sanitize security properties stored within project files. This oversight may allow an attacker to exploit type confusion, leading to the potential execution of arbitrary code within the affected applications. Organizations using these products should assess their installation for any impacted versions and take necessary measures to mitigate risks.

Affected Version(s)

SIMATIC S7-PLCSIM V17 0

SIMATIC STEP 7 V17 0

SIMATIC STEP 7 V18 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40759 : Code Execution Vulnerability in SIMATIC S7-PLCSIM and Related Siemens Products