CVE-2025-40944
published 2026-01-13CVE-2025-40944: A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0)…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
32.1th percentile
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions = V4.2.0 = V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 = V4.2.0 = V4.2.0 = V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state.
This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_et_200al_im_157-1_pn | < * | * |
| siemens | simatic_et_200mp_im_155-5_pn_hf | >= V4.2.0 < * | * |
| siemens | simatic_et_200sp_im_155-6_mf_hf | < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_2_hf | >= V4.2.0 < V4.2.5 | V4.2.5 |
| siemens | simatic_et_200sp_im_155-6_pn_3_hf | < V4.2.2 | V4.2.2 |
| siemens | simatic_et_200sp_im_155-6_pn_ha | < V1.3 | V1.3 |
| siemens | simatic_et_200sp_im_155-6_pn_r1 | < V6.0.1 | V6.0.1 |
| siemens | simatic_pn_mf_coupler | < * | * |
| siemens | simatic_pn_pn_coupler | < V6.0.0 | V6.0.0 |
| siemens | siplus_et_200mp_im_155-5_pn_hf | >= V4.2.0 < * | * |
| siemens | siplus_et_200mp_im_155-5_pn_hf_t1_rail | >= V4.2.0 < * | * |
| siemens | siplus_et_200sp_im_155-6_pn_hf | >= V4.2.0 < V4.2.5 | V4.2.5 |
| siemens | siplus_et_200sp_im_155-6_pn_hf_t1_rail | >= V4.2.0 < V4.2.5 | V4.2.5 |
| siemens | siplus_et_200sp_im_155-6_pn_hf_tx_rail | >= V4.2.0 < V4.2.5 | V4.2.5 |
| siemens | siplus_net_pn_pn_coupler | < V6.0.0 | V6.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC and SIPLUS products
cisa_ics·2026-01-14·CVSS 7.5
[HIGH] Siemens SIMATIC and SIPLUS products
ICS Advisory
##
Siemens SIMATIC and SIPLUS products
Release DateJanuary 14, 2026
Alert CodeICSA-26-015-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Siemens ET 200SP contains a denial-of-service vulnerability that could be triggered by sending a valid S7 protocol Disconnect Request (COTP DR TPDU), causing the device to become unresponsive and require a power cycle to recover. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens SIMATIC and SIPLUS products are affected
GHSA
GHSA-vqmm-3555-wq2q: A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA0
ghsa_unreviewed·2026-01-13
CVE-2025-40944 [HIGH] CWE-400 GHSA-vqmm-3555-wq2q: A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA0
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions = V4.2.0), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions = V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-13
Published