logo

Industrial Alert: Critical Stored XSS Vulnerability Discovered in Siemens SIMATIC S7-1500

ID: e8e4e841-1451-5d58-a20b-cd8059a2e450

STIX ID: report--e8e4e841-1451-5d58-a20b-cd8059a2e450

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical Stored Cross-Site Scripting (XSS) vulnerability (CVE-2025-40943, CVSS 9.6) was disclosed in the Siemens SIMATIC S7-1500 CPU family and related devices; an attacker can cause an authorized user to import a crafted trace file via the web interface to inject malicious code, potentially enabling unauthorized control or data theft in industrial environments. Siemens has released firmware updates for many affected products and recommends restricting web access, validating trace files, and monitoring for anomalous web-interface activity while fixes for some models are prepared.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.