Publication Date:
Last Update:
Current Version: V1.1
CVSS v3.1 Base Score: 9.8
Un-/Collapse All
Affected Product and Versions Remediation

All versions
affected by CVE-2025-15467
Currently no fix is available


All versions < V1.8.0
affected by CVE-2025-15467


All versions < V3.3.2
affected by CVE-2025-15467


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is planned


All versions
affected by CVE-2025-15467
Currently no fix is planned

Expand children
Expand children
Expand children
Expand children

All versions >= V4.0.700
affected by CVE-2025-15467
Contact customer support


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is planned


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available

Expand children

All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available

Expand children

All versions
affected by CVE-2025-15467
Currently no fix is available

Expand children

All versions < V5.7 SP4
affected by CVE-2025-15467


All versions
affected by CVE-2025-15467
Currently no fix is available

Expand children
Expand children

All versions < V17 Update 9
affected by CVE-2025-15467
Update to V17 Update 9 or later version



All versions < V21
affected by CVE-2025-15467


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions >= V6.3
affected by CVE-2025-15467
Currently no fix is available


All versions >= V6.3
affected by CVE-2025-15467
Currently no fix is available


All versions >= V6.3
affected by CVE-2025-15467
Currently no fix is available


All versions >= V6.3
affected by CVE-2025-15467
Currently no fix is available


All versions >= V6.3
affected by CVE-2025-15467
Currently no fix is available


All versions < V1.0 SP2 Update 5
affected by CVE-2025-15467
Update to V1.0 SP2 Update 5 or later version



All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions < V4.2 SP3
affected by CVE-2025-15467
Update to V4.2 SP3 or later version



All versions
affected by CVE-2025-15467
Currently no fix is available


All versions
affected by CVE-2025-15467
Currently no fix is available


All versions < V2.15.3.0
affected by CVE-2025-15467


All versions
affected by CVE-2025-15467
Currently no fix is available

Un-/Collapse All
Known Not Affected Products Reason
Expand children
Show more details
Expand children
Show more details
Expand children
Show more details
Expand children
Show more details
Expand children
Show more details
  • The hardening instructions mentioned in the products security concept should be followed
  • As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.
  • Do not accept files from untrusted and unvalidated sources in the affected applications

Product-specific remediations or mitigations can be found in the section Known Affected Products.
Please follow the General Security Recommendations.

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Un-/Collapse All

This chapter describes all vulnerabilities (CVE-IDs) addressed in this security advisory. Wherever applicable, it also documents the product-specific impact of the individual vulnerabilities.

CVSS v3.1 Base Score 9.8
CVSS v3.1 Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-787: Out-of-bounds Write

https://www.siemens.com/cert/advisories
V1.0 (2026-06-09): Publication Date
V1.1 (2026-07-14): Added SCALANCE X-200 family, X-200IRT family, X-200RNA family, X-300/408 family, SC-600 family to Known Not Affected and fix for SINUMERIK Access MyMachine /OPC UA , SIMOVE Fleetmanager. Updated remediation to No fix planned for SIMATIC Comfort/Mobile RT