CVE-2025-30033: Siemens TIA Portal/SIMATIC: DLL hijack in installer

HIGH
Published August 12, 2025
CISO Take

This is a classic uncontrolled-search-path (CWE-427) DLL hijacking flaw in the shared setup/installer component used across roughly 140 Siemens industrial automation products, including TIA Portal, SIMATIC WinCC, PCS 7, and STEP 7 — an attacker who can place a malicious DLL in the installer's search path can get arbitrary code to run with the privileges of whoever runs the install. The CVSS is high (7.8) because compromise, integrity, and availability impact are all rated High, but the actual exploitation likelihood is low: EPSS sits at just 0.2% (89th percentile is a relative ranking, not a real-world probability signal here), the CVE is not in CISA KEV, CISA's own SSVC decision is the lowest-urgency "TRACK" tier, and there is no public exploit code or Nuclei template. Critically, despite the platform's "ml_ui" tag, none of the ~140 affected products (TIA Portal, SIMATIC engineering tools, WinCC, PCS 7, etc.) are AI/ML software — this is a generic OT/ICS engineering-workstation risk, not an AI supply-chain or model-pipeline issue, and it should not be prioritized through an AI-risk lens. Action: track Siemens advisory SSA-282044 for per-product patch availability, only run installers from Siemens-verified sources/signed packages, and avoid executing setup files from shared or attacker-writable directories on OT engineering workstations.

Sources: NVD EPSS OpenSSF cert-portal.siemens.com

What is the risk?

Local attack vector with required user interaction (AC:L/PR:N/UI:R) caps real-world exploitability: an attacker needs to get a crafted DLL onto a path the installer will search (e.g., a shared drive, Downloads folder, or removable media) and then get a user to run the legitimate installer from that location. If successful, impact is severe (full C/I/A compromise of the host), which is why the base CVSS score is high. However, EPSS (0.2%), absence from CISA KEV, absence of public exploit code or scanner templates, and CISA's own "TRACK" SSVC decision all indicate low near-term exploitation likelihood. Net assessment: high potential impact, low current likelihood — standard patch-cycle priority rather than emergency response, unless the affected engineering workstations sit in a highly sensitive OT/ICS segment.

How does the attack unfold?

Initial Positioning
Attacker plants a malicious DLL in a writable location earlier in the DLL search order than the legitimate installer library (e.g., a shared install staging folder or removable media).
User Execution
A technician or engineer runs the legitimate Siemens setup component from that location, unaware the directory has been tampered with.
Code Execution
Windows DLL search-order behavior loads the attacker's DLL instead of the genuine library, executing arbitrary code with the installing user's privileges.
Impact
Attacker gains a foothold on the OT/engineering workstation, with potential follow-on access to industrial automation configuration and control assets.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Panel pip — No patch
5.8K OpenSSF 6.7 505 dependents Pushed 6d ago 68% patched ~15d to patch Full package profile →
Automation License Manager V6.0 — — No patch
Automation License Manager V6.2 — — No patch
CEMAT V10.0 — — No patch
CP PtP Param configuring interface — — No patch
Create MyConfig (CMC) — — No patch
Energy Support Library (EnSL) — — No patch
FM Configuration Package — — No patch
Modular PID CTRL Tool — — No patch
MultiFieldbus Configuration Tool (MFCT) — — No patch
OpenPCS 7 V10.0 — — No patch
OpenPCS 7 V9.1 — — No patch
SIMATIC Automation Tool — — No patch
SIMATIC Automation Tool SDK Windows — — No patch
SIMATIC BATCH V10.0 — — No patch
SIMATIC BATCH V9.1 — — No patch
SIMATIC Control Function Library (CFL) V1.x — — No patch
SIMATIC Control Function Library (CFL) V2.x — — No patch
SIMATIC Control Function Library (CFL) V3.x — — No patch
SIMATIC Control Function Library (CFL) V4.x — — No patch
SIMATIC Energy Suite V17 — — No patch
SIMATIC Energy Suite V18 — — No patch
SIMATIC Energy Suite V19 — — No patch
SIMATIC Logon V1.6 — — No patch
SIMATIC Logon V2.0 — — No patch
SIMATIC MTP CREATOR V3.x — — No patch
SIMATIC MTP CREATOR V4.x — — No patch
SIMATIC MTP CREATOR V2.x — — No patch
SIMATIC MTP CREATOR V5.x — — No patch
SIMATIC MTP Integrator V1.x — — No patch
SIMATIC MTP Integrator V2.x — — No patch
SIMATIC Management Agent — — No patch
SIMATIC Management Console — — No patch
SIMATIC NET PC Software V16 — — No patch
SIMATIC NET PC Software V17 — — No patch
SIMATIC NET PC Software V18 — — No patch
SIMATIC NET PC Software V19 — — No patch
SIMATIC NET PC Software V20 — — No patch
SIMATIC ODK 1500S — — No patch
SIMATIC PCS 7 Advanced Process Faceplates V9.1 — — No patch
SIMATIC PCS 7 Advanced Process Functions V2.1 — — No patch
SIMATIC PCS 7 Advanced Process Functions V2.2 — — No patch
SIMATIC PCS 7 Advanced Process Graphics V10.0 — — No patch
SIMATIC PCS 7 Advanced Process Graphics V9.1 — — No patch
SIMATIC PCS 7 Advanced Process Library V9.1 — — No patch
SIMATIC PCS 7 Advanced Process Library incl. Faceplates V10.0 — — No patch
SIMATIC PCS 7 Basis Faceplates V9.1 — — No patch
SIMATIC PCS 7 Basis Library V10.0 — — No patch
SIMATIC PCS 7 Basis Library V9.1 — — No patch
SIMATIC PCS 7 Industry Library V10.0 — — No patch
SIMATIC PCS 7 Industry Library V9.0 — — No patch
SIMATIC PCS 7 Industry Library V9.1 — — No patch
SIMATIC PCS 7 Logic Matrix V10.0 — — No patch
SIMATIC PCS 7 Logic Matrix V9.1 — — No patch
SIMATIC PCS 7 MPC Configurator — — No patch
SIMATIC PCS 7 PowerControl — — No patch
SIMATIC PCS 7 Standard Chemical Library V10.0 — — No patch
SIMATIC PCS 7 Standard Chemical Library V9.1 — — No patch
SIMATIC PCS 7 TeleControl — — No patch
SIMATIC PCS 7 V10.0 — — No patch
SIMATIC PCS 7 V9.1 — — No patch
SIMATIC PCS 7/OPEN OS V9.1 — — No patch
SIMATIC PCS neo V5.0 — — No patch
SIMATIC PCS neo V6.0 — — No patch
SIMATIC PDM Maintenance Station V5.0 — — No patch
SIMATIC PDM V9.2 — — No patch
SIMATIC PDM V9.3 — — No patch
SIMATIC ProSave V17 — — No patch
SIMATIC ProSave V18 — — No patch
SIMATIC ProSave V19 — — No patch
SIMATIC ProSave V20 — — No patch
SIMATIC Process Function Library (PFL) V4.0 — — No patch
SIMATIC Process Historian 2020 — — No patch
SIMATIC Process Historian 2022 — — No patch
SIMATIC Process Historian 2024 — — No patch
SIMATIC Route Control V10.0 — — No patch
SIMATIC Route Control V9.1 — — No patch
SIMATIC S7 F Systems V6.3 — — No patch
SIMATIC S7 F Systems V6.4 — — No patch
SIMATIC S7-1500 Software Controller V2 — — No patch
SIMATIC S7-1500 Software Controller V3 — — No patch
SIMATIC S7-Fail-safe Configuration Tool (S7-FCT) — — No patch
SIMATIC S7-PCT — — No patch
SIMATIC S7-PLCSIM Advanced — — No patch
SIMATIC S7-PLCSIM V17 — — No patch
SIMATIC S7-PLCSIM V18 — — No patch
SIMATIC S7-PLCSIM V19 — — No patch
SIMATIC S7-PLCSIM V20 — — No patch
SIMATIC STEP 7 CFC V19 — — No patch
SIMATIC STEP 7 CFC V20 — — No patch
SIMATIC STEP 7 V5.7 — — No patch
SIMATIC Safety Matrix — — No patch
SIMATIC Target — — No patch
SIMATIC WinCC Runtime Advanced — — No patch
SIMATIC WinCC Runtime Professional — — No patch
SIMATIC WinCC Runtime Professional V20 — — No patch
SIMATIC WinCC TeleControl — — No patch
SIMATIC WinCC Unified Line Coordination — — No patch
SIMATIC WinCC Unified PC Runtime V18 — — No patch
SIMATIC WinCC Unified PC Runtime V19 — — No patch
SIMATIC WinCC Unified PC Runtime V20 — — No patch
SIMATIC WinCC Unified Sequence — — No patch
SIMATIC WinCC V7.5 — — No patch
SIMATIC WinCC V8.0 — — No patch
SIMATIC WinCC V8.1 — — No patch
SIMATIC WinCC Visualization Architect (SiVArc) V17 — — No patch
SIMATIC WinCC Visualization Architect (SiVArc) V18 — — No patch
SIMATIC WinCC Visualization Architect (SiVArc) V19 — — No patch
SIMATIC WinCC Visualization Architect (SiVArc) V20 — — No patch
SIMATIC WinCC flexible ES — — No patch
SIMATIC eaSie Core Package — — No patch
SIMATIC eaSie Document Skills — — No patch
SIMATIC eaSie PCS 7 Skill Package — — No patch
SIMATIC eaSie Workflow Skills — — No patch
SIMATIC D7-SYS — — No patch
SIMIT Rapid Tester — — No patch
SIMIT Simulation Platform — — No patch
SINAMICS Startdrive V17 — — No patch
SINAMICS Startdrive V18 — — No patch
SINAMICS Startdrive V19 — — No patch
SINAMICS Startdrive V20 — — No patch
SINEC NMS — — No patch
SINEMA Remote Connect Client — — No patch
SITRANS — — No patch
Siemens Network Planner (SINETPLAN) — — No patch
Standard PID CTRL Tool — — No patch
TIA Administrator — — No patch
TIA Portal Cloud Connector — — No patch
TIA Portal Test Suite V17 — — No patch
TIA Portal Test Suite V18 — — No patch
TIA Portal Test Suite V19 — — No patch
TIA Portal Test Suite V20 — — No patch
TIA Project-Server — — No patch
TIA Project-Server V17 — — No patch
TeleControl Server Basic V3.1 — — No patch
Totally Integrated Automation Portal (TIA Portal) V17 — — No patch
Totally Integrated Automation Portal (TIA Portal) V18 — — No patch
Totally Integrated Automation Portal (TIA Portal) V19 — — No patch
Totally Integrated Automation Portal (TIA Portal) V20 — — No patch

How severe is it?

CVSS 3.1
7.8 / 10
EPSS
0.2%
chance of exploitation in 30 days
Higher than 9% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Local
AC Low
PR None
UI Required
S Unchanged
C High
I High
A High

What should I do?

1 step
  1. 1) Consult Siemens ProductCERT advisory SSA-282044 for the specific patched versions/hotfixes per affected product and apply them via normal OT change control. 2) Only download and run Siemens installers from official, verified sources — never from shared network drives, email attachments, or removable media of unknown provenance. 3) Verify installer digital signatures before execution. 4) Restrict write permissions on directories from which installers are staged/run (Downloads, Temp, shared install shares) to prevent DLL planting. 5) Detection: monitor engineering workstations for anomalous unsigned DLL loads during setup execution (Sysmon Event ID 7 / Image Load) correlated with installer processes for the listed Siemens products.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Code Execution Framework

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2025-30033?

This is a classic uncontrolled-search-path (CWE-427) DLL hijacking flaw in the shared setup/installer component used across roughly 140 Siemens industrial automation products, including TIA Portal, SIMATIC WinCC, PCS 7, and STEP 7 — an attacker who can place a malicious DLL in the installer's search path can get arbitrary code to run with the privileges of whoever runs the install. The CVSS is high (7.8) because compromise, integrity, and availability impact are all rated High, but the actual exploitation likelihood is low: EPSS sits at just 0.2% (89th percentile is a relative ranking, not a real-world probability signal here), the CVE is not in CISA KEV, CISA's own SSVC decision is the lowest-urgency "TRACK" tier, and there is no public exploit code or Nuclei template. Critically, despite the platform's "ml_ui" tag, none of the ~140 affected products (TIA Portal, SIMATIC engineering tools, WinCC, PCS 7, etc.) are AI/ML software — this is a generic OT/ICS engineering-workstation risk, not an AI supply-chain or model-pipeline issue, and it should not be prioritized through an AI-risk lens. Action: track Siemens advisory SSA-282044 for per-product patch availability, only run installers from Siemens-verified sources/signed packages, and avoid executing setup files from shared or attacker-writable directories on OT engineering workstations.

Is CVE-2025-30033 actively exploited?

No confirmed active exploitation of CVE-2025-30033 has been reported, but organizations should still patch proactively.

How to fix CVE-2025-30033?

1) Consult Siemens ProductCERT advisory SSA-282044 for the specific patched versions/hotfixes per affected product and apply them via normal OT change control. 2) Only download and run Siemens installers from official, verified sources — never from shared network drives, email attachments, or removable media of unknown provenance. 3) Verify installer digital signatures before execution. 4) Restrict write permissions on directories from which installers are staged/run (Downloads, Temp, shared install shares) to prevent DLL planting. 5) Detection: monitor engineering workstations for anomalous unsigned DLL loads during setup execution (Sysmon Event ID 7 / Image Load) correlated with installer processes for the listed Siemens products.

What is the CVSS score for CVE-2025-30033?

CVE-2025-30033 has a CVSS v3.1 base score of 7.8 (HIGH). The EPSS exploitation probability is 0.21%.

What are the technical details?

Original Advisory

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Exploitation Scenario

An attacker with local or network-share access to an OT engineering workstation plants a malicious DLL (named to match what the Siemens setup component expects) into a writable directory that sits earlier in the Windows DLL search order than the legitimate library location — for example a shared install staging folder or a USB drive. A technician or engineer then launches the legitimate Siemens installer from that same location to install or update TIA Portal, WinCC, or another affected product. Windows' DLL search-order behavior causes the attacker's DLL to load and execute before the genuine one, giving the attacker code execution with the installing user's privileges — potentially providing an initial foothold on an OT engineering workstation with access to plant/pull PLC and SCADA configurations.

Weaknesses (CWE)

CWE-427 — Uncontrolled Search Path Element: The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

  • [Architecture and Design, Implementation] Hard-code the search path to a set of known-safe values (such as system directories), or only allow them to be specified by the administrator in a configuration file. Do not allow these settings to be modified by an external party. Be careful to avoid related weaknesses such as CWE-426 and CWE-428.
  • [Implementation] When invoking other programs, specify those programs using fully-qualified pathnames. While this is an effective approach, code that uses fully-qualified pathnames might not be portable to other systems that do not use the same pathnames. The portability can be improved by locating the full-qualified paths in a centralized, easily-modifiable location within the source code, and having the code refer to these paths.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Timeline

Published
August 12, 2025
Last Modified
September 8, 2026
First Seen
August 11, 2026

Related Vulnerabilities