A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens simatic Siemens simatic Pcs Neo |
|
| Vendors & Products |
Siemens
Siemens simatic Siemens simatic Pcs Neo |
Tue, 09 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition. | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-09-09T08:48:05.138Z
Updated: 2025-09-09T19:34:10.734Z
Reserved: 2025-04-16T08:50:26.973Z
Link: CVE-2025-40798
Updated: 2025-09-09T19:34:05.792Z
Status : Awaiting Analysis
Published: 2025-09-09T09:15:38.160
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-40798
No data.