A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-40816

CVE-2025-40816: Siemens LOGO! PLC RCE Vulnerability

CVE-2025-40816 is a remote code execution vulnerability in Siemens LOGO! PLC devices that allows unauthenticated attackers to manipulate IP addresses and disrupt device reachability. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published: June 2, 2026

CVE-2025-40816 Overview

CVE-2025-40816 affects Siemens LOGO! 8 series logic modules and their SIPLUS variants across all firmware versions. The devices fail to perform certain validations during network interactions. An unauthenticated attacker on an adjacent network can manipulate the device IP address, rendering the controller unreachable. The flaw maps to [CWE-306] Missing Authentication for Critical Function. Siemens disclosed the issue in advisory SSA-267056.

Critical Impact

Unauthenticated adjacent-network attackers can change the IP configuration of LOGO! programmable logic controllers (PLCs), disrupting industrial process visibility and control until the device is physically reconfigured.

Affected Products

  • Siemens LOGO! 12/24RCE, 12/24RCEo, 230RCE, 230RCEo, 24CE, 24CEo, 24RCE, 24RCEo (all versions)
  • SIPLUS LOGO! 12/24RCE, 12/24RCEo, 230RCE, 230RCEo (all versions)
  • SIPLUS LOGO! 24CE, 24CEo, 24RCE, 24RCEo (all versions)

Discovery Timeline

  • 2025-11-11 - CVE-2025-40816 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-40816

Vulnerability Analysis

The Siemens LOGO! 8 family is a compact programmable logic controller (PLC) used in small automation deployments such as building control, HVAC, and lighting. The affected modules expose network services for configuration and programming but do not authenticate or validate certain management requests before acting on them. An attacker on the same logical network segment can send crafted requests that overwrite the device IP address.

Once the IP is changed, engineering stations, SCADA frontends, and monitoring systems lose connectivity to the controller. The PLC continues to run its ladder logic, but operators cannot read telemetry, push program updates, or trigger remote stops. Recovery requires physical access to the device to reset network parameters, increasing downtime for distributed installations.

Root Cause

The root cause is missing authentication for a critical function [CWE-306]. The LOGO! firmware accepts network configuration changes without verifying the identity of the requester. No credential check, session token, or cryptographic validation gates the IP reassignment path.

Attack Vector

Exploitation requires adjacent network access, meaning the attacker must reach the same broadcast domain or routed segment as the controller. No user interaction or privileges are required. The attacker sends a configuration request to the LOGO! device, supplying an arbitrary IP address. The device applies the change without challenge, severing legitimate management sessions. No verified public proof-of-concept code is currently available for this vulnerability. Refer to the Siemens Security Advisory SSA-267056 for protocol-level details.

Detection Methods for CVE-2025-40816

Indicators of Compromise

  • Unexpected IP address changes on LOGO! controllers reported by engineering workstations or asset inventory tools.
  • Loss of connectivity between SCADA/HMI systems and one or more LOGO! PLCs without corresponding maintenance activity.
  • ARP table changes on operational technology (OT) switches showing LOGO! MAC addresses bound to new IP addresses.

Detection Strategies

  • Monitor OT network traffic for unsolicited configuration commands directed at LOGO! devices on TCP/UDP ports used by the LOGO! protocol.
  • Correlate DHCP and ARP logs to identify unauthorized hosts issuing management traffic toward PLC subnets.
  • Use passive industrial protocol analyzers to baseline LOGO! configuration messages and alert on deviations.

Monitoring Recommendations

  • Enable network flow logging on switches and firewalls that segment the LOGO! subnet, retaining records for at least 90 days.
  • Track device reachability with continuous ICMP and protocol-level health checks, alerting on sudden disappearance of LOGO! endpoints.
  • Audit any host with management access to the OT segment for unauthorized scanning or configuration tooling.

How to Mitigate CVE-2025-40816

Immediate Actions Required

  • Restrict access to LOGO! controllers to trusted engineering hosts using firewall and switch access control lists.
  • Place LOGO! devices on dedicated VLANs isolated from corporate and general-purpose IT networks.
  • Review the Siemens Security Advisory SSA-267056 for current vendor guidance.
  • Inventory all LOGO! 8 and SIPLUS LOGO! modules and document their network exposure.

Patch Information

Siemens lists all versions of the affected LOGO! 8 and SIPLUS LOGO! product lines as vulnerable. No fixed firmware version is identified in the NVD record at publication. Operators should consult Siemens Security Advisory SSA-267056 for the latest remediation status and apply firmware updates when Siemens releases them.

Workarounds

  • Apply Siemens defense-in-depth recommendations: operate the devices only within protected IT environments and behind industrial security appliances.
  • Block adjacent-network access to LOGO! management ports using OT firewalls or unidirectional gateways where feasible.
  • Disable or physically disconnect LOGO! Ethernet interfaces on units that do not require network connectivity.
  • Implement network access control (802.1X) on OT switches to prevent unauthorized devices from joining the PLC segment.
bash
# Example: restrict LOGO! subnet access at the firewall
# Permit only the engineering workstation to reach the LOGO! VLAN
iptables -A FORWARD -s 10.20.30.10/32 -d 10.20.40.0/24 -j ACCEPT
iptables -A FORWARD -d 10.20.40.0/24 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeRCE

  • Vendor/TechLogo

  • SeverityHIGH

  • CVSS Score7.2

  • EPSS Probability0.05%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-306
  • Technical References
  • Siemens Security Advisory SSA-267056
  • Latest CVEs
  • CVE-2026-49199: Acer Predator Connect W6x Firmware RCE Flaw

  • CVE-2026-46344: Openquantumsafe Liboqs DOS Vulnerability

  • CVE-2026-44518: Openquantumsafe Liboqs DoS Vulnerability

  • CVE-2026-42951: MacGregor VDR Information Disclosure Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English