VYPR
Unrated severityNVD Advisory· Published May 13, 2025· Updated May 13, 2025

CVE-2025-40566

CVE-2025-40566

Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SIMATIC PCS neo fails to invalidate sessions on logout, letting an attacker reuse a stolen token for unauthorized access.

Vulnerability

SIMATIC PCS neo V4.1 (all versions prior to V4.1 Update 3) and SIMATIC PCS neo V5.0 (all versions prior to V5.0 Update 1) do not correctly invalidate user sessions upon user logout [1]. This allows a previously valid session token to remain usable even after the legitimate user has ended their session [1].

Exploitation

An attacker must first obtain a valid session token through other means (e.g., network eavesdropping, cross-site scripting, or physical access). No authentication is required for the reuse step. The attacker can then present the captured token to the affected system, and the system will accept it as a valid authenticated session, bypassing the logout state [1].

Impact

A remote, unauthenticated attacker who successfully reuses a session token gains unauthorized access to the SIMATIC PCS neo web interface with the privileges of the victim user. This can lead to information disclosure, manipulation of control system data, or disruption of industrial processes, depending on the victim's permissions. The CVSS v3.1 base score is 8.8 (High) [1].

Mitigation

Siemens has released fixes in SIMATIC PCS neo V4.1 Update 3 and V5.0 Update 1 [1]. Users should update to the latest versions. As a general practice, Siemens recommends protecting network access with appropriate mechanisms and following operational guidelines for industrial security [1].

References
  1. SSA-339086

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.