Buffer Overflow Vulnerability in SIMATIC PCS neo and UMC by Siemens
CVE-2025-40795
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-40795?
A vulnerability exists in Siemens SIMATIC PCS neo systems and the User Management Component (UMC) that is characterized by a stack-based buffer overflow. This issue enables an unauthenticated remote attacker to potentially execute arbitrary code or initiate a denial of service condition, thereby compromising the integrity and availability of the affected systems. The problem is present across all versions of SIMATIC PCS neo V4.1 and V5.0, and in UMC versions prior to V2.15.1.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC PCS neo V4.1 0
SIMATIC PCS neo V5.0 0
SIMATIC PCS neo V6.0 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved