Buffer Overflow Vulnerability in SIMATIC PCS neo and UMC by Siemens
CVE-2025-40795

9.3CRITICAL

What is CVE-2025-40795?

A vulnerability exists in Siemens SIMATIC PCS neo systems and the User Management Component (UMC) that is characterized by a stack-based buffer overflow. This issue enables an unauthenticated remote attacker to potentially execute arbitrary code or initiate a denial of service condition, thereby compromising the integrity and availability of the affected systems. The problem is present across all versions of SIMATIC PCS neo V4.1 and V5.0, and in UMC versions prior to V2.15.1.3.

Affected Version(s)

SIMATIC PCS neo V4.1 0

SIMATIC PCS neo V5.0 0

User Management Component (UMC) 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.