CVE-2025-40771
Description
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.4.24). Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.
Summary dbcve.org
The SIMATIC CP 1542SP-1 and CP 1543SP-1 communication processors contain an authentication bypass vulnerability in their configuration interface. Affected devices fail to properly authenticate configuration connections, allowing an unauthenticated remote attacker to access sensitive configuration data without any credentials.
Mitigation
Upgrade SIMATIC CP devices to firmware version V2.4.24 or later. Alternatively, implement network segmentation and firewall rules to restrict access to the configuration interface to only trusted networks/management stations.