CVE-2025-40771 is a missing-authentication vulnerability affecting Siemens SIMATIC and SIPLUS industrial communication processors, including SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0), and SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0), in all firmware versions prior to V2.4.24. The affected devices do not properly authenticate configuration connections. Based on the provided content, the root cause is the absence of authentication logic in the configuration connection handling path. As a result, a remote attacker can establish a configuration session without valid credentials and access device configuration data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass / missing authentication vulnerability in Siemens SIMATIC CP and SIPLUS ET 200SP communication processor devices where configuration connections are not properly authenticated, enabling unauthenticated remote access to configuration data.
A missing authentication vulnerability in Siemens SIMATIC and SIPLUS industrial communication processors that allows remote unauthenticated attackers with network access to retrieve or modify configuration data via the configuration interface.
A data confidentiality vulnerability in Siemens SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, and CP 1543SP-1 modules prior to version 2.4.24, allowing attackers to compromise data confidentiality.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.