CVE-2025-40759 | Siemens TIA Portal Cloud V20 Project File Parser deserialization (ssa-493396)

SecurityVulns

A vulnerability, which was classified as critical, was found in Siemens SIMATIC S7-PLCSIM V17, SIMATIC STEP 7 V17, SIMATIC STEP 7 V18, SIMATIC STEP 7 V19, SIMATIC STEP 7 V20, SIMATIC WinCC V17, SIMATIC WinCC V18, SIMATIC WinCC V19, SIMATIC WinCC V20, SIMOCODE ES V17, SIMOCODE ES V18, SIMOCODE ES V19, SIMOCODE ES V20, SIMOTION SCOUT TIA V5.4, SIMOTION SCOUT TIA V5.5, SIMOTION SCOUT TIA V5.6, SIMOTION SCOUT TIA V5.7, SINAMICS Startdrive V17, SINAMICS Startdrive V18, SINAMICS Startdrive V19, SINAMICS Startdrive V20, SIRIUS Safety ES V17, SIRIUS Safety ES V18, SIRIUS Safety ES V19, SIRIUS Safety ES V20, SIRIUS Soft Starter ES V17, SIRIUS Soft Starter ES V18, SIRIUS Soft Starter ES V19, SIRIUS Soft Starter ES V20, TIA Portal Cloud V17, TIA Portal Cloud V18, TIA Portal Cloud V19 and TIA Portal Cloud V20. This affects an unknown part of the component Project File Parser. The manipulation leads to deserialization.

This vulnerability is uniquely identified as CVE-2025-40759. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More