CVE-2025-30033

HIGH
Published August 12, 2025

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup...

Full CISO analysis pending enrichment.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Panel pip No patch
5.7K OpenSSF 6.9 499 dependents Pushed 4d ago 61% patched ~16d to patch Full package profile →
Automation License Manager V6.0 No patch
Automation License Manager V6.2 No patch
CEMAT V10.0 No patch
CP PtP Param configuring interface No patch
Create MyConfig (CMC) No patch
Energy Support Library (EnSL) No patch
FM Configuration Package No patch
Modular PID CTRL Tool No patch
MultiFieldbus Configuration Tool (MFCT) No patch
OpenPCS 7 V10.0 No patch
OpenPCS 7 V9.1 No patch
SIMATIC Automation Tool No patch
SIMATIC Automation Tool SDK Windows No patch
SIMATIC BATCH V10.0 No patch
SIMATIC BATCH V9.1 No patch
SIMATIC Control Function Library (CFL) V1.x No patch
SIMATIC Control Function Library (CFL) V2.x No patch
SIMATIC Control Function Library (CFL) V3.x No patch
SIMATIC Control Function Library (CFL) V4.x No patch
SIMATIC Energy Suite V17 No patch
SIMATIC Energy Suite V18 No patch
SIMATIC Energy Suite V19 No patch
SIMATIC Logon V1.6 No patch
SIMATIC Logon V2.0 No patch
SIMATIC MTP CREATOR V3.x No patch
SIMATIC MTP CREATOR V4.x No patch
SIMATIC MTP CREATOR V2.x No patch
SIMATIC MTP CREATOR V5.x No patch
SIMATIC MTP Integrator V1.x No patch
SIMATIC MTP Integrator V2.x No patch
SIMATIC Management Agent No patch
SIMATIC Management Console No patch
SIMATIC NET PC Software V16 No patch
SIMATIC NET PC Software V17 No patch
SIMATIC NET PC Software V18 No patch
SIMATIC NET PC Software V19 No patch
SIMATIC NET PC Software V20 No patch
SIMATIC ODK 1500S No patch
SIMATIC PCS 7 Advanced Process Faceplates V9.1 No patch
SIMATIC PCS 7 Advanced Process Functions V2.1 No patch
SIMATIC PCS 7 Advanced Process Functions V2.2 No patch
SIMATIC PCS 7 Advanced Process Graphics V10.0 No patch
SIMATIC PCS 7 Advanced Process Graphics V9.1 No patch
SIMATIC PCS 7 Advanced Process Library V9.1 No patch
SIMATIC PCS 7 Advanced Process Library incl. Faceplates V10.0 No patch
SIMATIC PCS 7 Basis Faceplates V9.1 No patch
SIMATIC PCS 7 Basis Library V10.0 No patch
SIMATIC PCS 7 Basis Library V9.1 No patch
SIMATIC PCS 7 Industry Library V10.0 No patch
SIMATIC PCS 7 Industry Library V9.0 No patch
SIMATIC PCS 7 Industry Library V9.1 No patch
SIMATIC PCS 7 Logic Matrix V10.0 No patch
SIMATIC PCS 7 Logic Matrix V9.1 No patch
SIMATIC PCS 7 MPC Configurator No patch
SIMATIC PCS 7 PowerControl No patch
SIMATIC PCS 7 Standard Chemical Library V10.0 No patch
SIMATIC PCS 7 Standard Chemical Library V9.1 No patch
SIMATIC PCS 7 TeleControl No patch
SIMATIC PCS 7 V10.0 No patch
SIMATIC PCS 7 V9.1 No patch
SIMATIC PCS 7/OPEN OS V9.1 No patch
SIMATIC PCS neo V5.0 No patch
SIMATIC PCS neo V6.0 No patch
SIMATIC PDM Maintenance Station V5.0 No patch
SIMATIC PDM V9.2 No patch
SIMATIC PDM V9.3 No patch
SIMATIC ProSave V17 No patch
SIMATIC ProSave V18 No patch
SIMATIC ProSave V19 No patch
SIMATIC ProSave V20 No patch
SIMATIC Process Function Library (PFL) V4.0 No patch
SIMATIC Process Historian 2020 No patch
SIMATIC Process Historian 2022 No patch
SIMATIC Process Historian 2024 No patch
SIMATIC Route Control V10.0 No patch
SIMATIC Route Control V9.1 No patch
SIMATIC S7 F Systems V6.3 No patch
SIMATIC S7 F Systems V6.4 No patch
SIMATIC S7-1500 Software Controller V2 No patch
SIMATIC S7-1500 Software Controller V3 No patch
SIMATIC S7-Fail-safe Configuration Tool (S7-FCT) No patch
SIMATIC S7-PCT No patch
SIMATIC S7-PLCSIM Advanced No patch
SIMATIC S7-PLCSIM V17 No patch
SIMATIC S7-PLCSIM V18 No patch
SIMATIC S7-PLCSIM V19 No patch
SIMATIC S7-PLCSIM V20 No patch
SIMATIC STEP 7 CFC V19 No patch
SIMATIC STEP 7 CFC V20 No patch
SIMATIC STEP 7 V5.7 No patch
SIMATIC Safety Matrix No patch
SIMATIC Target No patch
SIMATIC WinCC Runtime Advanced No patch
SIMATIC WinCC Runtime Professional No patch
SIMATIC WinCC Runtime Professional V20 No patch
SIMATIC WinCC TeleControl No patch
SIMATIC WinCC Unified Line Coordination No patch
SIMATIC WinCC Unified PC Runtime V18 No patch
SIMATIC WinCC Unified PC Runtime V19 No patch
SIMATIC WinCC Unified PC Runtime V20 No patch
SIMATIC WinCC Unified Sequence No patch
SIMATIC WinCC V7.5 No patch
SIMATIC WinCC V8.0 No patch
SIMATIC WinCC V8.1 No patch
SIMATIC WinCC Visualization Architect (SiVArc) V17 No patch
SIMATIC WinCC Visualization Architect (SiVArc) V18 No patch
SIMATIC WinCC Visualization Architect (SiVArc) V19 No patch
SIMATIC WinCC Visualization Architect (SiVArc) V20 No patch
SIMATIC WinCC flexible ES No patch
SIMATIC eaSie Core Package No patch
SIMATIC eaSie Document Skills No patch
SIMATIC eaSie PCS 7 Skill Package No patch
SIMATIC eaSie Workflow Skills No patch
SIMATIC D7-SYS No patch
SIMIT Rapid Tester No patch
SIMIT Simulation Platform No patch
SINAMICS Startdrive V17 No patch
SINAMICS Startdrive V18 No patch
SINAMICS Startdrive V19 No patch
SINAMICS Startdrive V20 No patch
SINEC NMS No patch
SINEMA Remote Connect Client No patch
SITRANS No patch
Siemens Network Planner (SINETPLAN) No patch
Standard PID CTRL Tool No patch
TIA Administrator No patch
TIA Portal Cloud Connector No patch
TIA Portal Test Suite V17 No patch
TIA Portal Test Suite V18 No patch
TIA Portal Test Suite V19 No patch
TIA Portal Test Suite V20 No patch
TIA Project-Server No patch
TIA Project-Server V17 No patch
TeleControl Server Basic V3.1 No patch
Totally Integrated Automation Portal (TIA Portal) V17 No patch
Totally Integrated Automation Portal (TIA Portal) V18 No patch
Totally Integrated Automation Portal (TIA Portal) V19 No patch
Totally Integrated Automation Portal (TIA Portal) V20 No patch

How severe is it?

CVSS 3.1
7.8 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
N/A

What is the attack surface?

AV AC PR UI S C I A
AV Local
AC Low
PR None
UI Required
S Unchanged
C High
I High
A High

What should I do?

No patch available

Monitor for updates. Consider compensating controls or temporary mitigations.

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2025-30033?

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Is CVE-2025-30033 actively exploited?

No confirmed active exploitation of CVE-2025-30033 has been reported, but organizations should still patch proactively.

How to fix CVE-2025-30033?

No patch is currently available. Monitor vendor advisories for updates.

What is the CVSS score for CVE-2025-30033?

CVE-2025-30033 has a CVSS v3.1 base score of 7.8 (HIGH).

What are the technical details?

Original Advisory

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Weaknesses (CWE)

CWE-427 — Uncontrolled Search Path Element: The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

  • [Architecture and Design, Implementation] Hard-code the search path to a set of known-safe values (such as system directories), or only allow them to be specified by the administrator in a configuration file. Do not allow these settings to be modified by an external party. Be careful to avoid related weaknesses such as CWE-426 and CWE-428.
  • [Implementation] When invoking other programs, specify those programs using fully-qualified pathnames. While this is an effective approach, code that uses fully-qualified pathnames might not be portable to other systems that do not use the same pathnames. The portability can be improved by locating the full-qualified paths in a centralized, easily-modifiable location within the source code, and having the code refer to these paths.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Timeline

Published
August 12, 2025
Last Modified
August 11, 2026
First Seen
August 11, 2026

Related Vulnerabilities