CVE-2025-40944: A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SI...
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions < V1.3), SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0) (All versions < V6.0.1), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (All versions >= V4.2.0 < V4.2.5), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions < V4.2.2), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (All versions), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (All versions < V6.0.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state.
This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.
Security readout for executives and security teams
Plain-English summary
Certain Siemens SIMATIC ET 200 interface modules and PN couplers can be forced into an unresponsive state by a valid S7 disconnect request over TCP port 102. The impact is operational downtime: affected devices may require a physical power cycle to recover.
Executive priority
Treat as a high-priority operational resilience issue for sites using affected Siemens distributed I/O or coupler devices. Prioritize environments where production depends on these devices and where TCP/102 is reachable beyond tightly controlled automation networks.
Technical view
The issue is improper handling of S7 protocol Disconnect Request COTP DR TPDUs on TCP/102, causing an improper session state and denial of service. CVSS v4.0 is 8.7 with network attack vector, low complexity, no privileges, no user interaction, and high availability impact.
Likely exposure
Exposure is most likely in industrial networks using the listed Siemens SIMATIC ET 200 or SIPLUS interface modules and PN/MF or PN/PN couplers where TCP/102 is reachable.
Exploitation context
The provided bundle does not show CISA KEV listing or confirmed active exploitation. The vulnerability is remotely reachable on a common Siemens S7 communications port, but the sources only support denial of service, not code execution or data compromise.
Researcher notes
Evidence supports CWE-400 resource management failure leading to availability loss. The bundle names many exact Siemens order numbers and version ranges, but does not provide exploit proof, KEV status, or universal fixed versions for every affected product.
Mitigation direction
Apply Siemens firmware updates or workarounds listed in SSA-674753 where available.
For products listed as all versions affected, follow current Siemens guidance before compensating controls.
Restrict TCP/102 access to required engineering and controller hosts only.
Segment affected industrial devices from enterprise, internet-facing, and remote-access networks.
Plan maintenance windows because recovery may require power cycling affected devices.
Validation and detection
Inventory exact Siemens product names, order numbers, and firmware versions.
Compare each asset against the affected-version ranges in CVE-2025-40944 and SSA-674753.
Confirm whether TCP/102 is reachable from non-control-network segments.
Review operations logs for unexplained device unresponsiveness requiring power cycling.
Verify remediation status against Siemens advisory guidance after maintenance.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-400: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-400 · source CWE mapping
Uncontrolled Resource Consumption
Uncontrolled Resource Consumption represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.