Vulnerabilities · 187 days ago

Siemens SIMATIC S7-1500 Code-Injection Flaw Affects Industrial Controllers

The web interface flaw can allow code injection if a legitimate user imports a specially crafted trace file. Siemens has released patches for multiple models and is preparing additional fixes.

CVE-2025-40943

NVD KEV

CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-13

Editions

Related stories