# Siemens SCALANCE, SIMATIC gear hit by CVE-2025-15467

Published: 2026-06-09 · Severity: high · Sectors: energy, manufacturing, infrastructure
Canonical: https://vorant.io/reports/3bf07133-3421-4f03-be94-2c3ab7fc5c83/siemens-scalance-simatic-gear-hit-by-cve-2025-15467

> Siemens issued advisory CERTFR-2026-AVI-0714 covering CVE-2025-15467, CVE-2026-24349, and CVE-2025-40808 affecting SCALANCE switches, SIMATIC HMI/WinCC systems, and SIPROTEC 5 devices—many without patches.

The French ANSSI published a security advisory documenting vulnerabilities in a broad range of Siemens industrial automation and networking equipment. CVE-2025-15467 affects dozens of SCALANCE switch families (LPE, M-series routers, XC/XF/XR-series switches), SIMATIC HMI panels, WinCC SCADA platforms, machine-vision products, and various IPC/IOT devices. CVE-2026-24349 impacts SIMATIC WinCC Unified PC Runtime versions 16 through 20. CVE-2025-40808 is specific to SIPROTEC 5 protection relays across CP100/CP150/CP200/CP300 variants. Risks include confidentiality breach, remote denial of service, and remote code execution.

Siemens has indicated that numerous affected products—particularly SCALANCE LPE9413/LPE9433, legacy WinCC V7.5/V8.0/V8.1, WinCC Unified PC Runtime V16–V20, and many SIPROTEC 5 CP100/CP200 models—will not receive security patches. Updates are available for SIMATIC HMI Basic/Comfort/Mobile Panels (update to ≥17.0.9), SIMATIC STEP 7 V5 (≥5.7.4), WinCC OA (3.19.024, 3.20.012, 3.21.02), WinCC Runtime Advanced V17 (≥17.0.9), WinCC Unified PC Runtime V21 (≥21.0.2), and WinCC Unified Sequence (≥21). Operators of affected infrastructure should review the CERT-FR bulletin for product-specific guidance and plan compensating controls where patches are unavailable.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15467, CVE-2025-40808, CVE-2026-24349

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0714

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3bf07133-3421-4f03-be94-2c3ab7fc5c83/siemens-scalance-simatic-gear-hit-by-cve-2025-15467.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
