ICSA-25-254-07
·
Published 2025-10-14
·
View on CISA ICS-CERT ↗
Siemens User Management Component (UMC)
CVSS 9.8
CRITICAL
Remediations
- In non-networked scenarios/deployments block TCP ports 4002 and 4004 on machines with UMC installed. If the deployment is not using the 'RT Server' type of UMC machine, port 4004 can be blocked everywhere without impacting network functionality for all other UMC machine-types (Server, Ring-Server, Agent).
- Currently no fix is planned
- Currently no fix is available
- Update to V2.15.1.3 or later version
Affected Vendors
Siemens
Affected Products (4)
Siemens
·
SIMATIC PCS neo V4.1
vers:all/*
Siemens
·
SIMATIC PCS neo V5.0
vers:all/*
Siemens
·
SIMATIC PCS neo V6.0
vers:all/*
Siemens
·
User Management Component (UMC)
vers:intdot/<2.15.1.3
Affected Sectors
Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more