CRITICAL

CVE-2025-40771

2025-10-14 CVSS v3.1
CVSS
9.8

Description

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.4.24). Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.

Summary dbcve.org

The SIMATIC CP 1542SP-1 and CP 1543SP-1 communication processors contain an authentication bypass vulnerability in their configuration interface. Affected devices fail to properly authenticate configuration connections, allowing an unauthenticated remote attacker to access sensitive configuration data without any credentials.

Mitigation

Upgrade SIMATIC CP devices to firmware version V2.4.24 or later. Alternatively, implement network segmentation and firewall rules to restrict access to the configuration interface to only trusted networks/management stations.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.53%
Probability of exploitation in next 30 days
43.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE