https://cert-portal.siemens.com/productcert/html/ssa-452276.html
https://support.industry.siemens.com/cs/ww/en/view/109478459/
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-04
Severity: Critical
ID: 505310
File Name: tenable_ot_siemens_CVE-2025-40943.nasl
Version: 1.2
Type: remote
Family: Tenable.ot
Published: 3/25/2026
Updated: 3/26/2026
Supported Sensors: Tenable OT Security
Risk Factor: Medium
Score: 6.7
Risk Factor: Critical
Base Score: 9.6
Temporal Score: 8.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Risk Factor: Critical
Base Score: 9.4
Threat Score: 7.7
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CPE: cpe:/o:siemens:siplus_s7-1500_cpu_firmware, cpe:/o:siemens:simatic_et_200sp_open_controller_cpu_1515sp_pc3_firmware, cpe:/o:siemens:siplus_et_200sp_cpu_firmware, cpe:/o:siemens:simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware, cpe:/o:siemens:simatic_s7-1500_cpu_firmware, cpe:/o:siemens:simatic_s7-1500_et_200pro_cpu_firmware, cpe:/o:siemens:simatic_et_200sp_open_controller_cpu_1515sp_pc_firmware, cpe:/o:siemens:simatic_s7-1500_cpu_firmware:4.1.2, cpe:/o:siemens:siplus_s7-1500_cpu_firmware:4.1.2, cpe:/o:siemens:simatic_et_200sp_cpu_firmware:4.1.2, cpe:/o:siemens:simatic_drive_controller_cpu_firmware, cpe:/o:siemens:simatic_et_200sp_cpu_firmware
Required KB Items: Tenable.ot/Siemens
Exploit Ease: No known exploits are available
Patch Publication Date: 3/10/2026
Vulnerability Publication Date: 3/10/2026
CVE: CVE-2025-40943
CWE: 95
ICSA: 26-071-04