A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens simatic Pcs Neo |
|
| CPEs | cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:*:-:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_1:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_2:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:5.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens simatic Pcs Neo |
Tue, 13 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout. | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:52.993Z
Updated: 2025-05-13T18:47:35.480Z
Reserved: 2025-04-16T08:20:17.031Z
Link: CVE-2025-40566
Updated: 2025-05-13T18:47:31.828Z
Status : Analyzed
Published: 2025-05-13T10:15:26.183
Modified: 2025-08-22T20:28:42.893
Link: CVE-2025-40566
No data.