CVE-2025-30033: Siemens Automation License Manager v6.0
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.
Affected products
- Siemens Automation License Manager v6.0: any version
- Siemens Automation License Manager v6.2: before V6.2 Upd3 (fixed in V6.2 Upd3)
- Siemens Cemat v10.0: any version
- Siemens CP Ptp Param Configuring Interface: any version
- Siemens Create Myconfig Cmc: before V6.9 (fixed in V6.9)
- Siemens Energy Support Library Ensl: any version
- Siemens Fm Configuration Package: any version
- Siemens Modular Pid Ctrl Tool: any version
- Siemens Multifieldbus Configuration Tool Mfct: before V1.5.5.0 (fixed in V1.5.5.0)
- Siemens Openpcs 7 v10.0: any version
- Siemens Openpcs 7 v9.1: any version
- Siemens Siemens Network Planner Sinetplan: before V2.0 SP2 (fixed in V2.0 SP2)
- Siemens SIMATIC Automation Tool: before V5.0 SP4 (fixed in V5.0 SP4)
- Siemens SIMATIC Automation Tool SDK Windows: before V5.0 SP4 (fixed in V5.0 SP4)
- Siemens SIMATIC Batch v10.0: any version
- Siemens SIMATIC Batch v9.1: any version
- Siemens SIMATIC Control Function Library Cfl v1.x: any version
- Siemens SIMATIC Control Function Library Cfl v2.x: any version
- Siemens SIMATIC Control Function Library Cfl v3.x: before V3.1.0.2 (fixed in V3.1.0.2)
- Siemens SIMATIC Control Function Library Cfl v4.x: before V4.1 (fixed in V4.1)
- Siemens SIMATIC d7-Sys: before V10.0 SP1 (fixed in V10.0 SP1)
- Siemens SIMATIC Easie Core Package: any version
- Siemens SIMATIC Easie Document Skills: any version
- Siemens SIMATIC Easie Pcs 7 Skill Package: any version
- Siemens SIMATIC Easie Workflow Skills: any version
- and 114 more
Published 2025-08-12. Last modified 2026-09-08.