CVE-2025-40795
published 2025-09-09CVE-2025-40795: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.66%
47.7th percentile
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code or to cause a denial of service condition.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs_neo | — | — |
| siemens | simatic_pcs_neo | — | — |
| siemens | simatic_pcs_neo_v4.1 | < * | * |
| siemens | simatic_pcs_neo_v5.0 | < * | * |
| siemens | simatic_pcs_neo_v6.0 | < V6.0 SP1 Update 1 | V6.0 SP1 Update 1 |
| siemens | user_management_component | < V2.15.1.3 | V2.15.1.3 |
| siemens | user_management_component | < 2.15.1.3 | 2.15.1.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted network messages targeting um.Ris.exe on TCP ports 4002 and 4004; unauthenticated remote exploitation of Message 17 triggers a stack-based buffer overflow in the UMC process. ↗
- →Alert on unexpected crashes or restarts of um.Ris.exe, which may indicate exploitation attempts via malformed/partial messages or oversized integer values sent to the UMC service. ↗
- →Block or alert on inbound TCP connections to ports 4002 and 4004 from untrusted/external networks on hosts running UMC; these are the attack-surface ports for all four CVEs in this advisory. ↗
- ·Port 4004 can be blocked on all non-RT-Server UMC machine types (Server, Ring-Server, Agent) without impacting network functionality; only RT Server deployments require port 4004 to remain open. ↗
- ·SIMATIC PCS neo V4.1 and V5.0 have no fix currently planned; mitigation relies solely on network-level controls (port blocking, firewall isolation). ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8mhf-qqpq-2vcr: A vulnerability has been identified in SIMATIC PCS neo V4
ghsa_unreviewed·2025-09-09
CVE-2025-40795 [CRITICAL] CWE-121 GHSA-8mhf-qqpq-2vcr: A vulnerability has been identified in SIMATIC PCS neo V4
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code or to cause a denial of service condition.
CISA ICS
Siemens User Management Component (UMC)
cisa_ics·2025-09-11·CVSS 9.8
[CRITICAL] Siemens User Management Component (UMC)
ICS Advisory
##
Siemens User Management Component (UMC)
Release DateSeptember 11, 2025
Alert CodeICSA-25-254-07
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: User Management Component (UMC)
- Vulnerabilities: Stack-based Buffer Overflow, Out-of-bounds Read
## 2. RISK EVALU
No detection rules found.
No public exploits indexed.
2025-09-09
Published