CVE-2025-40943
published 2026-03-10CVE-2025-40943: Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an authorized user…
PriorityP352critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.46%
36.9th percentile
Affected devices do not properly sanitize contents of trace files.
This could allow an attacker to inject code through social engineering an authorized user, who has the function right "Read diagnostics", to import a specially crafted trace file.
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_drive_controller_cpu_1504d_tf | < V3.1.6 | V3.1.6 |
| siemens | simatic_drive_controller_cpu_1507d_tf | < V3.1.6 | V3.1.6 |
| siemens | simatic_et_200sp_cpu_1510sp-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_et_200sp_cpu_1510sp-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1510sp_f-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_et_200sp_cpu_1510sp_f-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1512sp-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_et_200sp_cpu_1512sp-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1512sp_f-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_et_200sp_cpu_1512sp_f-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1514sp-2_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1514sp_f-2_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1514spt-2_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_cpu_1514spt_f-2_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc | < * | * |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2_v2_cpus_windows_os | < * | * |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2_v3_cpus_industrial_os | < * | * |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2_v3_cpus_windows_os | < * | * |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc3_v4_cpus | < * | * |
| siemens | simatic_s7-1500_cpu_1511-1_pn | < * | * |
| siemens | simatic_s7-1500_cpu_1511-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_s7-1500_cpu_1511-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_s7-1500_cpu_1511c-1_pn | < V2.9.9 | V2.9.9 |
| siemens | simatic_s7-1500_cpu_1511c-1_pn | < V4.1.2 | V4.1.2 |
| siemens | simatic_s7-1500_cpu_1511f-1_pn | < V2.9.9 | V2.9.9 |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2026-03-12·CVSS 9.6
[CRITICAL] Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 12, 2026
Alert CodeICSA-26-071-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIMATIC S7-1500 devices contain a vulnerability that could allow an attacker to inject code by tricking a legitimate user into importing a specially crafted trace file in the web interface. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens SIMATIC are affected:
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) vers:all/* (CVE-20
GHSA
GHSA-v7h2-5j7f-whwh: Affected devices do not properly sanitize contents of trace files
ghsa_unreviewed·2026-03-10
CVE-2025-40943 [CRITICAL] CWE-79 GHSA-v7h2-5j7f-whwh: Affected devices do not properly sanitize contents of trace files
Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate user to import a specially crafted trace file
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-10
Published