VYPR
High severity7.5NVD Advisory· Published May 13, 2025· Updated Jun 17, 2026

CVE-2025-30175

CVE-2025-30175

Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound write buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

23
  • Siemens Foundation/PCS neocpe-rescue5 versions
    0+ 4 more
    • (no CPE)range: 0
    • (no CPE)range: 0
    • cpe:2.3:a:siemens:simatic_pcs_neo:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:siemens:simatic_pcs_neo:5.0:*:*:*:*:*:*:*
    • (no CPE)range: All versions
  • cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*range: <4.0
    • (no CPE)range: 0
    • (no CPE)range: <V4.0
  • cpe:2.3:a:siemens:sinema_remote_connect:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:siemens:sinema_remote_connect:-:*:*:*:*:*:*:*
    • (no CPE)range: All versions
  • cpe:2.3:a:siemens:totally_integrated_automation_portal:17:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:siemens:totally_integrated_automation_portal:17:*:*:*:*:*:*:*
    • cpe:2.3:a:siemens:totally_integrated_automation_portal:18:*:*:*:*:*:*:*
    • cpe:2.3:a:siemens:totally_integrated_automation_portal:19:*:*:*:*:*:*:*
    • cpe:2.3:a:siemens:totally_integrated_automation_portal:20:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:user_management_component:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:siemens:user_management_component:*:*:*:*:*:*:*:*range: <2.15.1.1
    • (no CPE)range: 0
    • (no CPE)range: <V2.15.1.1
  • 0+ 4 more
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: V17, V18, V19, V20

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.