VDB
ICSA-25-289-07
ICSA-25-289-07
PUBLISHED
CVSS 9.800000190734863 CRITICAL
SIMATIC ET 200SP communication processors (CP 1542SP-1, CP 1542SP-1 IRC and CP 1543SP-1, incl. SIPLUS variants) contain an authentication vulnerability that could allow an unauthenticated remote attacker to access the configuration data. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) | ||
| SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) | ||
| SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) | ||
| SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) | ||
| SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) | ||
| SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) |
Exploit Intelligence
- https://cert-portal.siemens.com/productcert/csaf/ssa-486936.json (circl)
- https://cert-portal.siemens.com/productcert/html/ssa-486936.html (circl)
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-289-07.json (circl)
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-289-07 (circl)
- https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01 (circl)
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices (circl)
- https://www.cisa.gov/topics/industrial-control-systems (circl)
- https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf (circl)
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf (circl)
- https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b (circl)
…and 1 more exploits
Timeline
- Oct 14, 2025 CVE Published
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-486936.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-486936.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-289-07.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-289-07 advisory
- https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b url
- https://support.industry.siemens.com/cs/ww/en/view/109995159/ fix