Skip to main content
EPSS 0.4%top 63%

CVE-2025-40944: CWE-400: Uncontrolled Resource Consumption in Siemens SIMATIC ET 200AL IM 157-1 PN

0
High
VulnerabilityCVE-2025-40944cvecve-2025-40944cwe-400
Published: 01/13/2026 (01/13/2026, 09:44:05 UTC)
Source: CVE Database V5
Vendor/Project: Siemens
Product: SIMATIC ET 200AL IM 157-1 PN

Description

A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions < V1.3), SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0) (All versions < V6.0.1), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (All versions >= V4.2.0 < V4.2.5), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions < V4.2.2), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (All versions), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (All versions < V6.0.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state. This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Siemens

SIMATIC ET 200AL IM 157-1 PN

Affected versions
>=0

Siemens

SIMATIC ET 200MP IM 155-5 PN HF

Affected versions
>=4.2.0

Siemens

SIMATIC ET 200SP IM 155-6 MF HF

Affected versions
>=0

Siemens

SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants)

Affected versions
>=0 <1.3

Siemens

SIMATIC ET 200SP IM 155-6 PN R1

Affected versions
>=0 <6.0.1

Siemens

SIMATIC ET 200SP IM 155-6 PN/2 HF

Affected versions
>=4.2.0 <4.2.5

Siemens

SIMATIC ET 200SP IM 155-6 PN/3 HF

Affected versions
>=0 <4.2.2

Siemens

SIMATIC PN/MF Coupler

Affected versions
>=0

Siemens

SIMATIC PN/PN Coupler

Affected versions
>=0 <6.0.0

Siemens

SIPLUS ET 200MP IM 155-5 PN HF

Affected versions
>=4.2.0

Siemens

SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL

Affected versions
>=4.2.0

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

Affected versions
>=4.2.0 <4.2.5

Siemens

SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL

Affected versions
>=4.2.0 <4.2.5

Siemens

SIPLUS ET 200SP IM 155-6 PN HF TX RAIL

Affected versions
>=4.2.0 <4.2.5

Siemens

SIPLUS NET PN/PN Coupler

Affected versions
>=0 <6.0.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/09/2026, 10:31:35 UTC

Technical Analysis

This vulnerability (CVE-2025-40944) involves uncontrolled resource consumption (CWE-400) in Siemens SIMATIC ET 200AL IM 157-1 PN and related devices. When these devices receive a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, they mishandle the session disconnect, causing the device to enter an improper session state. This improper state leads to the device becoming unresponsive, effectively causing a denial-of-service (DoS) condition that requires a manual power cycle to restore normal operation. The vulnerability affects multiple Siemens SIMATIC ET 200 series devices across various version ranges, including all versions of some models and specific version intervals for others. The CVSS v3.1 base score is 7.5, indicating high severity, with network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to availability.

Potential Impact

Successful exploitation results in a denial-of-service condition where affected Siemens SIMATIC ET 200 devices become unresponsive and require a power cycle to recover. There is no impact on confidentiality or integrity, but availability is severely affected. This can disrupt industrial control processes relying on these devices.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, consider limiting network exposure of affected devices, especially blocking or monitoring TCP port 102 traffic to prevent malicious S7 protocol disconnect requests. Siemens or the vendor advisory should be monitored for updates and official remediation instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
siemens
Date Reserved
2025-04-16T09:06:15.879Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 696616cfa60475309f9ce613

Added to database: 01/13/2026, 09:56:31 UTC

Last enriched: 06/09/2026, 10:31:35 UTC

Last updated: 09/10/2026, 22:26:24 UTC

Views: 254

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses