Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14680 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout. |
Fri, 22 Aug 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens simatic Pcs Neo |
|
| CPEs | cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:*:-:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_1:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:4.1:update_2:*:*:*:*:*:* cpe:2.3:a:siemens:simatic_pcs_neo:5.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens simatic Pcs Neo |
Tue, 13 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout. | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-05-13T18:47:35.480Z
Reserved: 2025-04-16T08:20:17.031Z
Link: CVE-2025-40566
Updated: 2025-05-13T18:47:31.828Z
Status : Analyzed
Published: 2025-05-13T10:15:26.183
Modified: 2025-08-22T20:28:42.893
Link: CVE-2025-40566
No data.
OpenCVE Enrichment
No data.
EUVD