We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-40566



Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

Reserved 2025-04-16 | Published 2025-05-13 | Updated 2025-05-13 | Assigner siemens


HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-613: Insufficient Session Expiration

Product status

Default status
unknown

Any version before V4.1 Update 3
affected

Default status
unknown

Any version before V5.0 Update 1
affected

References

cert-portal.siemens.com/productcert/html/ssa-339086.html

cve.org (CVE-2025-40566)

nvd.nist.gov (CVE-2025-40566)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-40566

Support options

Helpdesk Chat, Email, Knowledgebase