CVE-2025-40584: XEE
A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT V5.7 (All versions < V5.7 SP1 HF1), SINAMICS STARTER V5.5 (All versions), SINAMICS STARTER V5.6 (All versions), SINAMICS STARTER V5.7 (All versions < V5.7 HF2). The affected application contains a XML External Entity Injection (XXE) vulnerability while parsing specially crafted XML files. This could allow an attacker to read arbitrary files in the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40584?
CVE-2025-40584 has been rated as critical due to its potential impact on system security.
How do I fix CVE-2025-40584?
To remediate CVE-2025-40584, update to the latest versions of SIMOTION SCOUT TIA and SIMOTION SCOUT as specified in the vendor's advisory.
Which versions are affected by CVE-2025-40584?
CVE-2025-40584 affects all versions of SIMOTION SCOUT TIA V5.4, V5.5, V5.6 (up to but not including V5.6 SP1 HF7), and V5.7 (up to but not including V5.7 SP1 HF1), along with all versions of SIMOTION SCOUT V5.4 and V5.5.
Is there a workaround for CVE-2025-40584?
Currently, there are no recommended workarounds for CVE-2025-40584; applying updates is the suggested mitigation.
Who should be concerned about CVE-2025-40584?
Organizations utilizing affected versions of SIMOTION SCOUT TIA and SIMOTION SCOUT should prioritize addressing CVE-2025-40584 to protect their systems.