Authentication Flaw in SIMATIC CP Products by Siemens
CVE-2025-40771
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-40771?
A security vulnerability has been discovered in various SIMATIC CP products by Siemens, which allows attackers to gain unauthorized access to configuration data. Devices that fall under this vulnerability do not adequately authenticate connections, making it possible for unauthenticated remote attackers to exploit this weakness and access sensitive configuration details. This flaw affects all versions of the specified products prior to V2.4.24. Addressing this issue promptly is critical for safeguarding the integrity of operations reliant on these devices.
Affected Version(s)
SIMATIC CP 1542SP-1 0
SIMATIC CP 1542SP-1 IRC 0
SIMATIC CP 1543SP-1 0
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved