PT-2025-6202 · Siemens · Simatic Ipc Diagbase+1

Felix Eberstaller

·

Published

2025-02-11

·

Updated

2025-02-11

·

CVE-2025-23403

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SIMATIC IPC DiagBase (All versions) SIMATIC IPC DiagMonitor (All versions)
Description: A vulnerability has been identified where the affected devices do not properly restrict user permissions for the registry key. This could allow an authenticated attacker to load vulnerable drivers into the system, leading to privilege escalation or bypassing endpoint protection and other security measures.
Recommendations: For SIMATIC IPC DiagBase, restrict access to the registry key to prevent unauthorized loading of drivers. For SIMATIC IPC DiagMonitor, limit user permissions to prevent exploitation of the vulnerability. As a temporary workaround, consider disabling the loading of vulnerable drivers into the system until a patch is available. Restrict access to the system to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2026-00195
CVE-2025-23403

Affected Products

Simatic Ipc Diagbase
Simatic Ipc Diagmonitor