PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40943 Siemens CVE debrief

CVE-2025-40943 is a critical trace-file sanitization issue affecting multiple Siemens SIMATIC controller families. CISA’s advisory says an attacker can socially engineer an authorized user with the "Read diagnostics" right to import a specially crafted trace file, which may execute code in the client browser session and trigger PLC operations the user is already permitted to perform.

Vendor
Siemens
Product
SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0)
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-05-14
Advisory published
2026-03-10
Advisory updated
2026-05-14

Who should care

OT and ICS defenders responsible for Siemens SIMATIC Drive Controller, ET 200SP, Open Controller, and S7-1500 deployments should treat this as urgent, especially where the webserver is enabled or where users hold the "Read diagnostics" function right. Organizations with exposed HTTP/HTTPS management interfaces or broad operator permissions should prioritize review first.

Technical summary

The flaw is caused by insufficient sanitization of trace file contents. According to the advisory, exploitation depends on social engineering a legitimate user who can read diagnostics and import a malicious trace file. Impact can include code execution in the client’s browser session and unauthorized PLC operations through the webserver using the victim’s existing privileges. The advisory maps the issue to CWE-95 and reports a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H.

Defensive priority

Urgent. The combination of remote reachability, user interaction, and potential PLC impact justifies immediate mitigation planning and firmware review, particularly for systems exposing the webserver.

Recommended defensive actions

  • Apply Siemens firmware updates where available: V3.1.6 or later, V2.9.9 or later, or V4.1.2 or later depending on the affected product line.
  • Disable the webserver if it is not required on affected systems.
  • Restrict access to TCP ports 80 and 443 to trusted IP addresses only.
  • Only upload trace files that are trusted and verified by your operational process.
  • Review and limit which users have the "Read diagnostics" right.
  • For affected product lines with no fix available in the advisory, rely on the documented mitigations and compensation controls.
  • Validate that the advisory revision applicable to your product matches the latest CISA/Siemens republication before maintenance planning.

Evidence notes

Primary evidence comes from the CISA CSAF republication of Siemens ProductCERT advisory SSA-452276 (ICSA-26-071-04), published 2026-03-10 and updated through 2026-05-14. The revision history shows later corrections to affected product coverage and fix versions, including updates on 2026-05-12 and 2026-05-14. The supplied corpus states that some product groups have vendor fixes while others list "Currently no fix is available."

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40943 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40943

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40943 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40943

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-452276.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-452276.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.