Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilityidentity-authentication-vulnerabilitycritical-infrastructure-threatwidely-deployed-product-advisory

Authentication Bypass Vulnerability in Siemens SIMATIC CP and SIPLUS ET 200SP Devices

Updated 3mo agoFirst seen Oct 15, 20252 sources

A critical authentication bypass vulnerability, tracked as CVE-2025-40771 with a CVSS score of 9.8, has been discovered in Siemens SIMATIC CP and SIPLUS ET 200SP industrial communication modules. The flaw affects multiple device models, including SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, as well as SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL, CP 1543SP-1 ISEC, and CP 1543SP-1 ISEC TX RAIL, specifically all versions prior to V2.4.24. The vulnerability arises from improper authentication of configuration connections, which allows unauthenticated remote attackers to gain access to sensitive configuration data on affected devices. This issue is particularly severe because it does not require any prior authentication, enabling attackers to exploit the flaw remotely without credentials. The vulnerability could be leveraged to compromise the integrity and confidentiality of industrial control systems that rely on these modules for network communication. Siemens has acknowledged the vulnerability and has released advisories to inform customers of the affected product versions. The flaw was reported by Siemens ProductCERT, and the company has urged users to update to the latest firmware version (V2.4.24 or later) to mitigate the risk. Exploitation of this vulnerability could allow attackers to alter device configurations, potentially disrupting industrial processes or enabling further attacks within operational technology environments. The vulnerability is considered critical due to the widespread use of these modules in industrial automation and the potential impact on critical infrastructure. Security researchers have highlighted the risk of remote exploitation, emphasizing the need for immediate patching and network segmentation to protect vulnerable devices. Organizations are advised to review their asset inventories to identify affected devices and prioritize remediation efforts. In addition to patching, Siemens recommends implementing network security best practices, such as restricting access to configuration interfaces and monitoring for unauthorized connection attempts. The disclosure of CVE-2025-40771 underscores the ongoing challenges in securing industrial control systems against remote attacks. The vulnerability was publicly disclosed in mid-October 2025, and security advisories have been disseminated to raise awareness among industrial operators. The incident highlights the importance of timely vulnerability management and the need for robust authentication mechanisms in critical infrastructure devices. Failure to address this vulnerability could result in significant operational disruptions and potential safety risks in industrial environments. The security community continues to monitor for signs of exploitation in the wild, and organizations are encouraged to stay informed about further updates from Siemens and relevant CERTs.

Share:
Authentication Bypass Vulnerability in Siemens SIMATIC CP and SIPLUS ET 200SP Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 14, 20258mo ago

Siemens recommends firmware updates to remediate CVE-2025-40771

Siemens advised customers to update impacted devices to firmware version V2.4.24 or later to address the authentication bypass vulnerability. Siemens rated the issue Critical, with a CVSS v3.1 score of 9.8 and CVSS v4.0 score of 9.3.

Siemens publishes advisory for CVE-2025-40771

Siemens ProductCERT published advisory SSA-486936 for CVE-2025-40771, a critical authentication bypass affecting multiple SIMATIC CP and SIPLUS ET 200SP communication processor models. The flaw allows remote unauthenticated access to configuration data because affected devices do not properly authenticate configuration connections.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
6 linked
Simatic Cp 1543sp-1Simatic Cp 1542sp-1Siplus Et 200sp Cp 1542sp-1 Irc Tx RailSiplus Et 200sp Cp 1543sp-1 Isec Tx RailSimatic Cp 1542sp-1 IrcSiplus Et 200sp Cp 1543sp-1 Isec
Organizations
1 linked
Siemens
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Authentication Bypass Vulnerability in Siemens SIMATIC CP and SIPLUS ET 200SP Devices | Mallory