CVE-2025-30174

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
13/05/2025
Last modified:
03/10/2025

Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:* 4.0 (excluding)
cpe:2.3:a:siemens:sinema_remote_connect:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:17:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:18:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:19:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:20:*:*:*:*:*:*:*
cpe:2.3:a:siemens:user_management_component:*:*:*:*:*:*:*:* 2.15.1.1 (excluding)


References to Advisories, Solutions, and Tools