CVE-2025-40944: CWE-400: Uncontrolled Resource Consumption in Siemens SIMATIC ET 200AL IM 157-1 PN
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions < V1.3), SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0) (All versions < V6.0.1), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (All versions >= V4.2.0 < V4.2.5), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions < V4.2.2), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (All versions), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (All versions < V6.0.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state. This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-40944) involves uncontrolled resource consumption (CWE-400) in Siemens SIMATIC ET 200AL IM 157-1 PN and related devices. When these devices receive a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, they mishandle the session disconnect, causing the device to enter an improper session state. This improper state leads to the device becoming unresponsive, effectively causing a denial-of-service (DoS) condition that requires a manual power cycle to restore normal operation. The vulnerability affects multiple Siemens SIMATIC ET 200 series devices across various version ranges, including all versions of some models and specific version intervals for others. The CVSS v3.1 base score is 7.5, indicating high severity, with network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to availability.
Potential Impact
Successful exploitation results in a denial-of-service condition where affected Siemens SIMATIC ET 200 devices become unresponsive and require a power cycle to recover. There is no impact on confidentiality or integrity, but availability is severely affected. This can disrupt industrial control processes relying on these devices.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, consider limiting network exposure of affected devices, especially blocking or monitoring TCP port 102 traffic to prevent malicious S7 protocol disconnect requests. Siemens or the vendor advisory should be monitored for updates and official remediation instructions.
CVE-2025-40944: CWE-400: Uncontrolled Resource Consumption in Siemens SIMATIC ET 200AL IM 157-1 PN
Description
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions < V1.3), SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0) (All versions < V6.0.1), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (All versions >= V4.2.0 < V4.2.5), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions < V4.2.2), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (All versions), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (All versions < V6.0.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state. This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.
CVSS v3.1
Score 7.5high
Affected software
Siemens
SIMATIC ET 200AL IM 157-1 PN
Siemens
SIMATIC ET 200MP IM 155-5 PN HF
Siemens
SIMATIC ET 200SP IM 155-6 MF HF
Siemens
SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants)
Siemens
SIMATIC ET 200SP IM 155-6 PN R1
Siemens
SIMATIC ET 200SP IM 155-6 PN/2 HF
Siemens
SIMATIC ET 200SP IM 155-6 PN/3 HF
Siemens
SIMATIC PN/MF Coupler
Siemens
SIMATIC PN/PN Coupler
Siemens
SIPLUS ET 200MP IM 155-5 PN HF
Siemens
SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL
Siemens
SIPLUS ET 200SP IM 155-6 PN HF
Siemens
SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL
Siemens
SIPLUS ET 200SP IM 155-6 PN HF TX RAIL
Siemens
SIPLUS NET PN/PN Coupler
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-40944) involves uncontrolled resource consumption (CWE-400) in Siemens SIMATIC ET 200AL IM 157-1 PN and related devices. When these devices receive a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, they mishandle the session disconnect, causing the device to enter an improper session state. This improper state leads to the device becoming unresponsive, effectively causing a denial-of-service (DoS) condition that requires a manual power cycle to restore normal operation. The vulnerability affects multiple Siemens SIMATIC ET 200 series devices across various version ranges, including all versions of some models and specific version intervals for others. The CVSS v3.1 base score is 7.5, indicating high severity, with network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to availability.
Potential Impact
Successful exploitation results in a denial-of-service condition where affected Siemens SIMATIC ET 200 devices become unresponsive and require a power cycle to recover. There is no impact on confidentiality or integrity, but availability is severely affected. This can disrupt industrial control processes relying on these devices.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, consider limiting network exposure of affected devices, especially blocking or monitoring TCP port 102 traffic to prevent malicious S7 protocol disconnect requests. Siemens or the vendor advisory should be monitored for updates and official remediation instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- siemens
- Date Reserved
- 2025-04-16T09:06:15.879Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 696616cfa60475309f9ce613
Added to database: 01/13/2026, 09:56:31 UTC
Last enriched: 06/09/2026, 10:31:35 UTC
Last updated: 09/10/2026, 22:26:24 UTC
Views: 254
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.