CVE-2025-40584: XEE

Published Aug 12, 2025
·
Updated

A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT V5.7 (All versions < V5.7 SP1 HF1), SINAMICS STARTER V5.5 (All versions), SINAMICS STARTER V5.6 (All versions), SINAMICS STARTER V5.7 (All versions < V5.7 HF2). The affected application contains a XML External Entity Injection (XXE) vulnerability while parsing specially crafted XML files. This could allow an attacker to read arbitrary files in the system.

Affected Software

3 affected components
Siemens SIMOTION SCOUT TIA=5.4, =5.5, <5.6 SP1 HF7, <5.7 SP1 HF1
Siemens SIMOTION Scout=5.4, =5.5, <5.6 SP1 HF7, <5.7 SP1 HF1
Siemens SINAMICS STARTER=5.5, =5.6, <5.7 HF2

Event History

Aug 12, 2025
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Oct 10, 57583
Event
via NVD·07:20 AM

Frequently Asked Questions

1

What is the severity of CVE-2025-40584?

CVE-2025-40584 has been rated as critical due to its potential impact on system security.

2

How do I fix CVE-2025-40584?

To remediate CVE-2025-40584, update to the latest versions of SIMOTION SCOUT TIA and SIMOTION SCOUT as specified in the vendor's advisory.

3

Which versions are affected by CVE-2025-40584?

CVE-2025-40584 affects all versions of SIMOTION SCOUT TIA V5.4, V5.5, V5.6 (up to but not including V5.6 SP1 HF7), and V5.7 (up to but not including V5.7 SP1 HF1), along with all versions of SIMOTION SCOUT V5.4 and V5.5.

4

Is there a workaround for CVE-2025-40584?

Currently, there are no recommended workarounds for CVE-2025-40584; applying updates is the suggested mitigation.

5

Who should be concerned about CVE-2025-40584?

Organizations utilizing affected versions of SIMOTION SCOUT TIA and SIMOTION SCOUT should prioritize addressing CVE-2025-40584 to protect their systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203