CVE-2025-40759 PUBLISHED

Assigner: siemens
Reserved: 16.04.2025 Published: 12.08.2025 Updated: 12.08.2025

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions), SIMATIC WinCC V17 (All versions), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions < V19 Update 4), SIMATIC WinCC V20 (All versions), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOCODE ES V20 (All versions), SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS Startdrive V19 (All versions), SINAMICS Startdrive V20 (All versions), SIRIUS Safety ES V17 (TIA Portal) (All versions), SIRIUS Safety ES V18 (TIA Portal) (All versions), SIRIUS Safety ES V19 (TIA Portal) (All versions), SIRIUS Safety ES V20 (TIA Portal) (All versions), SIRIUS Soft Starter ES V17 (TIA Portal) (All versions), SIRIUS Soft Starter ES V18 (TIA Portal) (All versions), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions), SIRIUS Soft Starter ES V20 (TIA Portal) (All versions), TIA Portal Cloud V17 (All versions), TIA Portal Cloud V18 (All versions), TIA Portal Cloud V19 (All versions < V5.2.1.1), TIA Portal Cloud V20 (All versions). Affected products do not properly sanitize stored security properties when parsing project files. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Siemens
Product SIMATIC S7-PLCSIM V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC STEP 7 V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC STEP 7 V18
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC STEP 7 V19
Versions Default: unknown
  • affected from 0 to V19 Update 4 (excl.)
Vendor Siemens
Product SIMATIC STEP 7 V20
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC WinCC V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC WinCC V18
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMATIC WinCC V19
Versions Default: unknown
  • affected from 0 to V19 Update 4 (excl.)
Vendor Siemens
Product SIMATIC WinCC V20
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOCODE ES V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOCODE ES V18
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOCODE ES V19
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOCODE ES V20
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOTION SCOUT TIA V5.4
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOTION SCOUT TIA V5.5
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIMOTION SCOUT TIA V5.6
Versions Default: unknown
  • affected from 0 to V5.6 SP1 HF7 (excl.)
Vendor Siemens
Product SIMOTION SCOUT TIA V5.7
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SINAMICS Startdrive V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SINAMICS Startdrive V18
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SINAMICS Startdrive V19
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SINAMICS Startdrive V20
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Safety ES V17 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Safety ES V18 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Safety ES V19 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Safety ES V20 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Soft Starter ES V17 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Soft Starter ES V18 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Soft Starter ES V19 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product SIRIUS Soft Starter ES V20 (TIA Portal)
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product TIA Portal Cloud V17
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product TIA Portal Cloud V18
Versions Default: unknown
  • affected from 0 to * (excl.)
Vendor Siemens
Product TIA Portal Cloud V19
Versions Default: unknown
  • affected from 0 to V5.2.1.1 (excl.)
Vendor Siemens
Product TIA Portal Cloud V20
Versions Default: unknown
  • affected from 0 to * (excl.)

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE