Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30175


A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound write buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.


Published

2025-05-13T10:15:24.103

Last Modified

2025-10-03T19:52:42.610

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens simatic_pcs_neo 4.1 Yes
Application siemens simatic_pcs_neo 5.0 Yes
Application siemens sinec_nms < 4.0 Yes
Application siemens sinema_remote_connect - Yes
Application siemens totally_integrated_automation_portal 17 Yes
Application siemens totally_integrated_automation_portal 18 Yes
Application siemens totally_integrated_automation_portal 19 Yes
Application siemens totally_integrated_automation_portal 20 Yes
Application siemens user_management_component < 2.15.1.1 Yes

References