CVE-2025-40771 is a critical vulnerability affecting Siemens SIMATIC CP 1542SP-1 and related industrial control system modules, specifically versions prior to V2.4.24. The flaw, categorized as CWE-306 (Missing Authentication for Critical Function), allows an unauthenticated remote attacker to access and potentially modify configuration data due to improper authentication on configuration connections. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a high risk of complete compromise (Confidentiality, Integrity, Availability) with low attack complexity and no user interaction required. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness within cybersecurity circles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | SIMATIC CP 1542SP-1 IRC | >= 0, < V2.4.24CNA affecteddefault unknown | |
| Siemens | SIMATIC CP 1542SP-1 | >= 0, < V2.4.24CNA affecteddefault unknown | |
| Siemens | SIMATIC CP 1543SP-1 | >= 0, < V2.4.24CNA affecteddefault unknown | |
| Siemens | SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL | >= 0, < V2.4.24CNA affecteddefault unknown | |
| Siemens | SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL | >= 0, < V2.4.24CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.