Record summary

CVE-2025-30174 has a selected CVSS score of 8.7 (high).

Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 13, 2025 · Source: CVE List

Affected products and versions

9
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore *affected

Default status: unknown

CVE ListBefore *affected

Default status: unknown

CVE ListBefore V4.0affected

Default status: unknown

CVE ListBefore *affected

Totally Integrated Automation Portal (TIA Portal) V17

Browse Siemens / Totally Integrated Automation Portal (TIA Portal) V17

Default status: unknown

CVE ListBefore *affected

Totally Integrated Automation Portal (TIA Portal) V18

Browse Siemens / Totally Integrated Automation Portal (TIA Portal) V18

Default status: unknown

CVE ListBefore *affected

Totally Integrated Automation Portal (TIA Portal) V19

Browse Siemens / Totally Integrated Automation Portal (TIA Portal) V19

Default status: unknown

CVE ListBefore *affected

Totally Integrated Automation Portal (TIA Portal) V20

Browse Siemens / Totally Integrated Automation Portal (TIA Portal) V20

Default status: unknown

CVE ListBefore *affected

Default status: unknown

CVE ListBefore V2.15.1.1affected

References

2