CVE-2025-30033: CWE-427: Uncontrolled Search Path Element in Siemens Automation License Manager V6.0
The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2025-30033 affects the setup component of Siemens Automation License Manager V6.0. It is categorized as CWE-427, indicating an uncontrolled search path element vulnerability. This weakness enables DLL hijacking, where an attacker can place a malicious DLL in a location that the setup component searches before the legitimate DLL, causing arbitrary code execution with the privileges of the installing user. Exploitation requires local access and user interaction (installation by a legitimate user). The CVSS 3.1 base score is 7.8, reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user performing the installation, potentially leading to full system compromise including confidentiality, integrity, and availability impacts. The attack vector is local with low attack complexity and no privileges required, but user interaction is necessary.
Mitigation Recommendations
No patch or official remediation information is currently available for this vulnerability. Patch status is not yet confirmed — check the Siemens vendor advisory for current remediation guidance. Until a fix is provided, users should exercise caution when installing applications that use the affected setup component and restrict local access to trusted users.
CVE-2025-30033: CWE-427: Uncontrolled Search Path Element in Siemens Automation License Manager V6.0
Description
The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.
CVSS v3.1
Score 7.8high
Affected software
Siemens
Automation License Manager V6.0
Siemens
Automation License Manager V6.2
Siemens
CEMAT V10.0
Siemens
CP PtP Param configuring interface
Siemens
Create MyConfig (CMC)
Siemens
Energy Support Library (EnSL)
Siemens
FM Configuration Package
Siemens
Modular PID CTRL Tool
Siemens
MultiFieldbus Configuration Tool (MFCT)
Siemens
OpenPCS 7 V10.0
Siemens
OpenPCS 7 V9.1
Siemens
Siemens Network Planner (SINETPLAN)
Siemens
SIMATIC Automation Tool
Siemens
SIMATIC Automation Tool SDK Windows
Siemens
SIMATIC BATCH V10.0
Siemens
SIMATIC BATCH V9.1
Siemens
SIMATIC Control Function Library (CFL) V1.x
Siemens
SIMATIC Control Function Library (CFL) V2.x
Siemens
SIMATIC Control Function Library (CFL) V3.x
Siemens
SIMATIC Control Function Library (CFL) V4.x
Siemens
SIMATIC D7-SYS
Siemens
SIMATIC eaSie Core Package
Siemens
SIMATIC eaSie Document Skills
Siemens
SIMATIC eaSie PCS 7 Skill Package
Siemens
SIMATIC eaSie Workflow Skills
Siemens
SIMATIC Energy Suite V17
Siemens
SIMATIC Energy Suite V18
Siemens
SIMATIC Energy Suite V19
Siemens
SIMATIC Logon V1.6
Siemens
SIMATIC Logon V2.0
Siemens
SIMATIC Management Agent
Siemens
SIMATIC Management Console
Siemens
SIMATIC MTP CREATOR V2.x
Siemens
SIMATIC MTP CREATOR V3.x
Siemens
SIMATIC MTP CREATOR V4.x
Siemens
SIMATIC MTP CREATOR V5.x
Siemens
SIMATIC MTP Integrator V1.x
Siemens
SIMATIC MTP Integrator V2.x
Siemens
SIMATIC NET PC Software V16
Siemens
SIMATIC NET PC Software V17
Siemens
SIMATIC NET PC Software V18
Siemens
SIMATIC NET PC Software V19
Siemens
SIMATIC NET PC Software V20
Siemens
SIMATIC ODK 1500S
Siemens
SIMATIC PCS 7 Advanced Process Faceplates V9.1
Siemens
SIMATIC PCS 7 Advanced Process Functions V2.1
Siemens
SIMATIC PCS 7 Advanced Process Functions V2.2
Siemens
SIMATIC PCS 7 Advanced Process Graphics V10.0
Siemens
SIMATIC PCS 7 Advanced Process Graphics V9.1
Siemens
SIMATIC PCS 7 Advanced Process Library incl. Faceplates V10.0
Siemens
SIMATIC PCS 7 Advanced Process Library V9.1
Siemens
SIMATIC PCS 7 Basis Faceplates V9.1
Siemens
SIMATIC PCS 7 Basis Library V10.0
Siemens
SIMATIC PCS 7 Basis Library V9.1
Siemens
SIMATIC PCS 7 Industry Library V10.0
Siemens
SIMATIC PCS 7 Industry Library V9.0
Siemens
SIMATIC PCS 7 Industry Library V9.1
Siemens
SIMATIC PCS 7 Logic Matrix V10.0
Siemens
SIMATIC PCS 7 Logic Matrix V9.1
Siemens
SIMATIC PCS 7 MPC Configurator
Siemens
SIMATIC PCS 7 PowerControl V9.1
Siemens
SIMATIC PCS 7 Standard Chemical Library V10.0
Siemens
SIMATIC PCS 7 Standard Chemical Library V9.1
Siemens
SIMATIC PCS 7 TeleControl V9.1
Siemens
SIMATIC PCS 7 V10.0
Siemens
SIMATIC PCS 7 V9.1
Siemens
SIMATIC PCS 7/OPEN OS V9.1
Siemens
SIMATIC PCS neo V5.0
Siemens
SIMATIC PCS neo V6.0
Siemens
SIMATIC PDM Maintenance Station V5.0
Siemens
SIMATIC PDM V9.2
Siemens
SIMATIC PDM V9.3
Siemens
SIMATIC Process Function Library (PFL) V4.0
Siemens
SIMATIC Process Historian 2020
Siemens
SIMATIC Process Historian 2022
Siemens
SIMATIC Process Historian 2024
Siemens
SIMATIC ProSave V17
Siemens
SIMATIC ProSave V18
Siemens
SIMATIC ProSave V19
Siemens
SIMATIC ProSave V20
Siemens
SIMATIC Route Control V10.0
Siemens
SIMATIC Route Control V9.1
Siemens
SIMATIC S7 F Systems V6.3
Siemens
SIMATIC S7 F Systems V6.4
Siemens
SIMATIC S7-1500 Software Controller V2
Siemens
SIMATIC S7-1500 Software Controller V3
Siemens
SIMATIC S7-Fail-safe Configuration Tool (S7-FCT)
Siemens
SIMATIC S7-PCT
Siemens
SIMATIC S7-PLCSIM Advanced
Siemens
SIMATIC S7-PLCSIM V17
Siemens
SIMATIC S7-PLCSIM V18
Siemens
SIMATIC S7-PLCSIM V19
Siemens
SIMATIC S7-PLCSIM V20
Siemens
SIMATIC Safety Matrix
Siemens
SIMATIC STEP 7 CFC V19
Siemens
SIMATIC STEP 7 CFC V20
Siemens
SIMATIC STEP 7 V5.7
Siemens
SIMATIC Target
Siemens
SIMATIC WinCC flexible ES
Siemens
SIMATIC WinCC Runtime Advanced
Siemens
SIMATIC WinCC Runtime Professional
Siemens
SIMATIC WinCC Runtime Professional V20
Siemens
SIMATIC WinCC TeleControl
Siemens
SIMATIC WinCC Unified Line Coordination
Siemens
SIMATIC WinCC Unified PC Runtime V18
Siemens
SIMATIC WinCC Unified PC Runtime V19
Siemens
SIMATIC WinCC Unified PC Runtime V20
Siemens
SIMATIC WinCC Unified Sequence
Siemens
SIMATIC WinCC V7.5
Siemens
SIMATIC WinCC V8.0
Siemens
SIMATIC WinCC V8.1
Siemens
SIMATIC WinCC Visualization Architect (SiVArc) V17
Siemens
SIMATIC WinCC Visualization Architect (SiVArc) V18
Siemens
SIMATIC WinCC Visualization Architect (SiVArc) V19
Siemens
SIMATIC WinCC Visualization Architect (SiVArc) V20
Siemens
SIMIT Rapid Tester
Siemens
SIMIT Simulation Platform
Siemens
SINAMICS Startdrive V17
Siemens
SINAMICS Startdrive V18
Siemens
SINAMICS Startdrive V19
Siemens
SINAMICS Startdrive V20
Siemens
SINEC NMS
Siemens
SINEMA Remote Connect Client
Siemens
SITRANS
Siemens
Standard PID CTRL Tool
Siemens
TeleControl Server Basic V3.1
Siemens
TIA Administrator
Siemens
TIA Portal Cloud Connector
Siemens
TIA Portal Test Suite V17
Siemens
TIA Portal Test Suite V18
Siemens
TIA Portal Test Suite V19
Siemens
TIA Portal Test Suite V20
Siemens
TIA Project-Server
Siemens
TIA Project-Server V17
Siemens
Totally Integrated Automation Portal (TIA Portal) V17
Siemens
Totally Integrated Automation Portal (TIA Portal) V18
Siemens
Totally Integrated Automation Portal (TIA Portal) V19
Siemens
Totally Integrated Automation Portal (TIA Portal) V20
Siemens
WinCC Panel Image Setup
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2025-30033 affects the setup component of Siemens Automation License Manager V6.0. It is categorized as CWE-427, indicating an uncontrolled search path element vulnerability. This weakness enables DLL hijacking, where an attacker can place a malicious DLL in a location that the setup component searches before the legitimate DLL, causing arbitrary code execution with the privileges of the installing user. Exploitation requires local access and user interaction (installation by a legitimate user). The CVSS 3.1 base score is 7.8, reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user performing the installation, potentially leading to full system compromise including confidentiality, integrity, and availability impacts. The attack vector is local with low attack complexity and no privileges required, but user interaction is necessary.
Mitigation Recommendations
No patch or official remediation information is currently available for this vulnerability. Patch status is not yet confirmed — check the Siemens vendor advisory for current remediation guidance. Until a fix is provided, users should exercise caution when installing applications that use the affected setup component and restrict local access to trusted users.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- siemens
- Date Reserved
- 2025-03-14T09:05:35.696Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 689b2661ad5a09ad003132c7
Added to database: 08/12/2025, 11:32:49 UTC
Last enriched: 08/11/2026, 13:07:41 UTC
Last updated: 09/10/2026, 19:41:54 UTC
Views: 142
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.