A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens simatic Pcs Neo |
|
CPEs | cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:*:-:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_1:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_2:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:5.0:-:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens simatic Pcs Neo |
Tue, 13 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout. | |
Weaknesses | CWE-613 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:52.993Z
Updated: 2025-05-13T18:47:35.480Z
Reserved: 2025-04-16T08:20:17.031Z
Link: CVE-2025-40566

Updated: 2025-05-13T18:47:31.828Z

Status : Analyzed
Published: 2025-05-13T10:15:26.183
Modified: 2025-08-22T20:28:42.893
Link: CVE-2025-40566

No data.