← Back to home
ICSA-25-072-09  ·  Published 2026-01-14  ·  View on CISA ICS-CERT ↗

Siemens OPC UA

CVSS 9.1 CRITICAL

Remediations

  • Currently no fix is planned
  • Update to V11.3 or later version
  • Update to V7.4 Update 7 or later version
  • Update to V7.5 Update 2 or later version
  • Please note that the affected functionality (HTTPS endpoint in OPC UA Server) is deactivated by default in Unified RT. Systems running with default configuration are therefore not affected by this vulnerability.
  • Please note that the affected functionality (HTTPS endpoint in OPC UA Server) is deactivated by default. Systems running with default configuration are therefore not affected by this vulnerability.
  • Currently no fix is available
  • Update to V19 Update 4 or later version
  • Update to V8.0 Update 3 or later version

Affected Vendors

Siemens

Affected Products (12)

Siemens · Industrial Edge for Machine Tools (formerly known as "SINUMERIK Edge") vers:all/*
Siemens · SIMATIC BRAUMAT vers:all/*
Siemens · SIMATIC Energy Manager PRO V7.2 vers:all/*
Siemens · SIMATIC Energy Manager PRO V7.3 vers:all/*
Siemens · SIMATIC Energy Manager PRO V7.4 >=V7.4Update0|<V7.4Update7
Siemens · SIMATIC Energy Manager PRO V7.5 >=V7.5Update0|<V7.5Update2
Siemens · SIMATIC IPC DiagMonitor vers:all/*
Siemens · SIMATIC SISTAR vers:all/*
Siemens · SIMATIC WinCC Unified V18 vers:all/*
Siemens · SIMATIC WinCC Unified V19 <V19_Update_4
Siemens · SIMATIC WinCC V8.0 <V8.0_Update_3
Siemens · SIMIT V11 vers:intdot/<11.3

Affected Sectors

Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more