CVE-2025-30033: Siemens Automation License Manager v6.0

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Affected products

  • Siemens Automation License Manager v6.0: any version
  • Siemens Automation License Manager v6.2: before V6.2 Upd3 (fixed in V6.2 Upd3)
  • Siemens Cemat v10.0: any version
  • Siemens CP Ptp Param Configuring Interface: any version
  • Siemens Create Myconfig Cmc: before V6.9 (fixed in V6.9)
  • Siemens Energy Support Library Ensl: any version
  • Siemens Fm Configuration Package: any version
  • Siemens Modular Pid Ctrl Tool: any version
  • Siemens Multifieldbus Configuration Tool Mfct: before V1.5.5.0 (fixed in V1.5.5.0)
  • Siemens Openpcs 7 v10.0: any version
  • Siemens Openpcs 7 v9.1: any version
  • Siemens Siemens Network Planner Sinetplan: before V2.0 SP2 (fixed in V2.0 SP2)
  • Siemens SIMATIC Automation Tool: before V5.0 SP4 (fixed in V5.0 SP4)
  • Siemens SIMATIC Automation Tool SDK Windows: before V5.0 SP4 (fixed in V5.0 SP4)
  • Siemens SIMATIC Batch v10.0: any version
  • Siemens SIMATIC Batch v9.1: any version
  • Siemens SIMATIC Control Function Library Cfl v1.x: any version
  • Siemens SIMATIC Control Function Library Cfl v2.x: any version
  • Siemens SIMATIC Control Function Library Cfl v3.x: before V3.1.0.2 (fixed in V3.1.0.2)
  • Siemens SIMATIC Control Function Library Cfl v4.x: before V4.1 (fixed in V4.1)
  • Siemens SIMATIC d7-Sys: before V10.0 SP1 (fixed in V10.0 SP1)
  • Siemens SIMATIC Easie Core Package: any version
  • Siemens SIMATIC Easie Document Skills: any version
  • Siemens SIMATIC Easie Pcs 7 Skill Package: any version
  • Siemens SIMATIC Easie Workflow Skills: any version
  • and 114 more

Published 2025-08-12. Last modified 2026-09-08.