Buffer Overflow Vulnerability in SIMATIC PCS neo and UMC by Siemens
CVE-2025-40795
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-40795?
A vulnerability exists in Siemens SIMATIC PCS neo systems and the User Management Component (UMC) that is characterized by a stack-based buffer overflow. This issue enables an unauthenticated remote attacker to potentially execute arbitrary code or initiate a denial of service condition, thereby compromising the integrity and availability of the affected systems. The problem is present across all versions of SIMATIC PCS neo V4.1 and V5.0, and in UMC versions prior to V2.15.1.3.
Affected Version(s)
SIMATIC PCS neo V4.1 0
SIMATIC PCS neo V5.0 0
User Management Component (UMC) 0