ICSA-25-254-07
·
Published 2026-07-07
·
View on CISA ICS-CERT ↗
Siemens User Management Component (UMC)
CVSS 9.8
CRITICAL
Risk Summary
Siemens' User Management Component (UMC) is affected by multiple vulnerabilities that could allow an unauthenticated remote attacker to execute arbitrary code or to cause a denial of service condition. Siemens has released a new version for User Management Component (UMC) and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Remediations
- In non-networked scenarios/deployments block TCP ports 4002 and 4004 on machines with UMC installed. If the deployment is not using the 'RT Server' type of UMC machine, port 4004 can be blocked everywhere without impacting network functionality for all other UMC machine-types (Server, Ring-Server, Agent).
- Currently no fix is planned
- Update to V2.15.1.3 or later version
- Update to V6.0 SP1 Update 1 or later version
Affected Vendors
Siemens
Affected Products (4)
Siemens
·
SIMATIC PCS neo V4.1
vers:all/*
Siemens
·
SIMATIC PCS neo V5.0
vers:all/*
Siemens
·
SIMATIC PCS neo V6.0
vers:intdot/<6.0.1.1
Siemens
·
User Management Component (UMC)
vers:intdot/<2.15.1.3
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more