CVE-2025-40771
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.4.24). Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.
Published:Oct 14, 2025
Last Modified:Apr 15, 2026
EPS:Oct 14, 2025
EPSS Score:0.00117
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
Simatic Cp 1542sp-1
Siemens
Simatic Cp 1542sp-1
Vendor
Siemens
Product
Simatic Cp 1542sp-1 Irc
Siemens
Simatic Cp 1542sp-1 Irc
Vendor
Siemens
Product
Simatic Cp 1543sp-1
Siemens
Simatic Cp 1543sp-1
Vendor
Siemens
Product
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail
Siemens
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail
Vendor
Siemens
Product
Siplus Et 200sp Cp 1543sp-1 Isec
Siemens
Siplus Et 200sp Cp 1543sp-1 Isec
Vendor
Siemens
Product
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail
Siemens
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
