← Back to home
ICSA-25-226-19  ·  Published 2025-08-12  ·  View on CISA ICS-CERT ↗

Siemens SINUMERIK

CVSS 8.3 HIGH

CVEs (1)

Remediations

  • Apply Defense-in-Depth
  • Close VNC port on X130 via HMI setting
  • Set VNC Password on X120 and X130
  • Change TCU.ini setting to "ExternalViewerReqTimeoutMode=0"
  • Update to V1.15 SP5 or later version Updated software version can be obtained from Siemens customer support or a local partner.
  • Update to V1.25 SP1 or later version Updated software version can be obtained from Siemens customer support or a local partner.
  • Update to V4.95 SP5 or later version Updated software version can be obtained from Siemens customer support or a local partner.
  • Update to V5.25 SP1 or later version Updated software version can be obtained from Siemens customer support or a local partner.
  • Update to V6.15 SP5 or later version Updated software version can be obtained from Siemens customer support or a local partner.
  • Update to V6.25 SP1 or later version Updated software version can be obtained from Siemens customer support or a local partner.

Affected Vendors

Siemens

Affected Products (7)

Siemens · SINUMERIK 828D PPU.4 <V4.95_SP5
Siemens · SINUMERIK 828D PPU.5 <V5.25_SP1
Siemens · SINUMERIK 840D sl <V4.95_SP5
Siemens · SINUMERIK MC <V1.25_SP1
Siemens · SINUMERIK MC V1.15 <V1.15_SP5
Siemens · SINUMERIK ONE <V6.25_SP1
Siemens · SINUMERIK ONE V6.15 <V6.15_SP5

Affected Sectors

Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more