CVE-2025-40771
Published: Oct 14, 2025
Modified: Oct 14, 2025
CVSS v3.1
9.8
Description
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.4.24). Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC CP 1542SP-1 | affected 0 - < V2.4.24 |
Siemens | SIMATIC CP 1542SP-1 IRC | affected 0 - < V2.4.24 |
Siemens | SIMATIC CP 1543SP-1 | affected 0 - < V2.4.24 |
Siemens | SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL | affected 0 - < V2.4.24 |
Siemens | SIPLUS ET 200SP CP 1543SP-1 ISEC | affected 0 - < V2.4.24 |
Siemens | SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL | affected 0 - < V2.4.24 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now