CVE-2025-40795: Buffer Overflow
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code or to cause a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40795?
CVE-2025-40795 is considered a high severity vulnerability due to its stack-based buffer overflow risks.
How do I fix CVE-2025-40795?
To mitigate CVE-2025-40795, update the User Management Component (UMC) to version 2.15.1.3 or later.
Which products are affected by CVE-2025-40795?
CVE-2025-40795 affects all versions of Siemens SIMATIC PCS neo V4.1 and V5.0, as well as UMC versions prior to 2.15.1.3.
What kind of vulnerability is CVE-2025-40795?
CVE-2025-40795 is identified as a stack-based buffer overflow vulnerability within the integrated UMC component.
Can CVE-2025-40795 be exploited remotely?
Yes, CVE-2025-40795 can potentially be exploited by an unauthorized user if they gain access to the affected systems.