Authentication Flaw in SIMATIC CP Products by Siemens
CVE-2025-40771
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-40771?
A security vulnerability has been discovered in various SIMATIC CP products by Siemens, which allows attackers to gain unauthorized access to configuration data. Devices that fall under this vulnerability do not adequately authenticate connections, making it possible for unauthenticated remote attackers to exploit this weakness and access sensitive configuration details. This flaw affects all versions of the specified products prior to V2.4.24. Addressing this issue promptly is critical for safeguarding the integrity of operations reliant on these devices.
Affected Version(s)
SIMATIC CP 1542SP-1 0
SIMATIC CP 1542SP-1 IRC 0
SIMATIC CP 1543SP-1 0