https://cert-portal.siemens.com/productcert/html/ssa-089022.html
https://support.industry.siemens.com/cs/ww/en/view/109997626/
Severity: Critical
ID: 505122
File Name: tenable_ot_siemens_CVE-2025-32433.nasl
Version: 1.2
Type: remote
Family: Tenable.ot
Published: 2/10/2026
Updated: 2/11/2026
Supported Sensors: Tenable OT Security
Risk Factor: Critical
Score: 10.0
Risk Factor: Critical
Base Score: 10
Temporal Score: 9.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C
CPE: cpe:/o:siemens:scalance_xrm334_%28230_v_ac%2c_8xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xcm324_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%2824v_dc%2c_2x10g%2c_24xsfp%2c_8xsfp%2b%29_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%2824_v_dc%2c_8xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xcm328_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%28230_v_ac%2c_12xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%2824_v_dc%2c_12xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%28230v_ac%2c_2x10g%2c_24xsfp%2c_8xsfp%2b%29_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%282x230v_ac%2c_2x10g%2c_24xsfp%2c_8xsfp%2b%29_firmware:3.3, cpe:/o:siemens:scalance_xrm334_%282x230_v_ac%2c_8xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xrh334_%2824_v_dc%2c_8xfo%2c_cc%29_firmware:3.3, cpe:/o:siemens:ruggedcom_rst2428p_firmware:3.3, cpe:/o:siemens:scalance_xcm332_firmware, cpe:/o:siemens:scalance_xrm334_%282x230_v_ac%2c_12xfo%29_firmware:3.3, cpe:/o:siemens:scalance_xch328_firmware:3.3
Required KB Items: Tenable.ot/Siemens
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 1/28/2026
Vulnerability Publication Date: 4/8/2025
CISA Known Exploited Vulnerability Due Dates: 6/30/2025
Metasploit (Erlang OTP Pre-Auth RCE Scanner and Exploit)
CVE: CVE-2025-32433
CWE: 306