CVE-2025-40943
CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
Una vulnerabilità nell'interfaccia web dei controller SIMATIC S7-1500 permette code injection se un utente importa un trace file appositamente creato (CVE-2025-40943). Siemens ha rilasciato patch per diversi modelli e prevede ulteriori fix.
1 fonte · 12 mar
CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36º percentile).
CISA Advisories
Siemens SIMATIC | CISA
Siemens SIMATIC Summary SIMATIC S7-1500 devices contain a vulnerability that could allow an attacker to inject code by tricking a legitimate user into importing a specially crafted trace file in the web interface.
originalePart of the PlainSec briefing for 2026-03-13
Every edition of this story: Falla di code injection nei controller SIMATIC S7-1500