📦 Simatic Pcs Neo

by Siemens

🔍 What is Simatic Pcs Neo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40795

CRITICAL CVSS 9.8 Sep 9, 2025

A stack-based buffer overflow vulnerability in Siemens SIMATIC PCS neo's User Management Component allows unauthenticated remote attackers to execute arbitrary code or cause denial of service. This af...

CVE-2021-20093

CRITICAL CVSS 9.1 Jun 16, 2021

CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter that allows unauthenticated remote attackers to read heap memory contents or cause denial of service. This affects CodeMete...

CVE-2025-40797

HIGH CVSS 7.5 Sep 9, 2025

An out-of-bounds read vulnerability in the User Management Component (UMC) of SIMATIC PCS neo industrial control systems allows unauthenticated remote attackers to cause denial of service. This affect...

CVE-2025-40566

HIGH CVSS 8.8 May 13, 2025

This vulnerability allows session hijacking in Siemens SIMATIC PCS neo industrial control systems. An attacker who obtains a valid session token can reuse it even after the legitimate user logs out, p...

CVE-2025-30176

HIGH CVSS 7.5 May 13, 2025

An out-of-bounds read buffer overflow vulnerability in Siemens' User Management Component (UMC) affects multiple industrial automation products. This allows unauthenticated remote attackers to cause d...

CVE-2023-46283

HIGH CVSS 7.5 Dec 12, 2023

This CVE describes a buffer overflow vulnerability in multiple Siemens industrial automation products. An attacker can send specially crafted requests to port 4002/tcp to cause an out-of-bounds write,...

CVE-2023-46285

HIGH CVSS 7.5 Dec 12, 2023

This vulnerability allows attackers to cause denial-of-service by sending specially crafted messages to port 4004/tcp on affected Siemens industrial software products. The service crashes but automati...

CVE-2023-46281

HIGH CVSS 7.1 Dec 12, 2023

This CVE describes an overly permissive CORS policy vulnerability in Siemens industrial software products. An attacker could exploit this by tricking legitimate users into visiting malicious websites,...

CVE-2021-41057

HIGH CVSS 7.1 Nov 14, 2021

This vulnerability in WIBU CodeMeter Runtime allows local attackers to overwrite arbitrary files via a crafted symbolic link attack. It affects systems running CodeMeter Runtime before version 7.30a, ...