CVE-2025-40943
CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
The web interface flaw can allow code injection if a legitimate user imports a specially crafted trace file. Siemens has released patches for multiple models and is preparing additional fixes.
1 source · Mar 12
CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36th percentile).
CISA Advisories
Siemens SIMATIC | CISA
Siemens SIMATIC Summary SIMATIC S7-1500 devices contain a vulnerability that could allow an attacker to inject code by tricking a legitimate user into importing a specially crafted trace file in the web interface.
originalPart of the PlainSec briefing for 2026-03-13
Every edition of this story: Siemens SIMATIC S7-1500 Code-Injection Flaw Affects Industrial Controllers