CVE-2025-40566: Critical severity siemens simatic pcs neo firmware vulnerability
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40566?
The severity of CVE-2025-40566 is classified as Medium due to the potential for session hijacking.
How do I fix CVE-2025-40566?
To fix CVE-2025-40566, upgrade to SIMATIC PCS neo V4.1 Update 3 or V5.0 Update 1 or later.
What products are affected by CVE-2025-40566?
CVE-2025-40566 affects SIMATIC PCS neo versions prior to V4.1 Update 3 and V5.0 Update 1.
Can CVE-2025-40566 be exploited remotely?
Yes, CVE-2025-40566 can be exploited remotely by an unauthenticated attacker who obtains a valid session.
What type of vulnerability is CVE-2025-40566?
CVE-2025-40566 is a session management vulnerability that fails to properly invalidate user sessions.