{"id":"CVE-2025-30033","title":"The affected setup component is vulnerable to DLL hijacking","summary":"The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-427"],"vendor":"Siemens","product":"Automation License Manager V6.0","affected":["automation_license_manager_v6.0 < *","automation_license_manager_v6.2 < V6.2 Upd3","cemat_v10.0 < *","cp_ptp_param_configuring_interface < *","create_myconfig_cmc < V6.9","energy_support_library_ensl < *","fm_configuration_package < *","modular_pid_ctrl_tool < *","multifieldbus_configuration_tool_mfct < V1.5.5.0","openpcs_7_v10.0 < *","openpcs_7_v9.1 < *","network_planner_sinetplan < V2.0 SP2","simatic_automation_tool < V5.0 SP4","simatic_automation_tool_sdk_windows < V5.0 SP4","simatic_batch_v10.0 < *","simatic_batch_v9.1 < *","simatic_control_function_library_cfl_v1.x < *","simatic_control_function_library_cfl_v2.x < *","simatic_control_function_library_cfl_v3.x < V3.1.0.2","simatic_control_function_library_cfl_v4.x < V4.1","simatic_d7-sys < V10.0 SP1","simatic_easie_core_package < *","simatic_easie_document_skills < *","simatic_easie_pcs_7_skill_package < *","simatic_easie_workflow_skills < *","simatic_energy_suite_v17 < *","simatic_energy_suite_v18 < *","simatic_energy_suite_v19 < V19 Update 4","simatic_logon_v1.6 < *","simatic_logon_v2.0 < V2.0 Upd3","simatic_management_agent < V9.1 SP1 Upd8","simatic_management_console < V9.1 SP1 Upd8","simatic_mtp_creator_v2.x < V2.1","simatic_mtp_creator_v3.x < *","simatic_mtp_creator_v4.x < V4.1.0.1","simatic_mtp_creator_v5.x < V5.0.0.1","simatic_mtp_integrator_v1.x < *","simatic_mtp_integrator_v2.x < *","simatic_net_pc_software_v16 < *","simatic_net_pc_software_v17 < *","simatic_net_pc_software_v18 < *","simatic_net_pc_software_v19 < *","simatic_net_pc_software_v20 < V20.0 Update 1","simatic_odk_1500s < *","simatic_pcs_7_advanced_process_faceplates_v9.1 < V9.1 SP2 Upd4","simatic_pcs_7_advanced_process_functions_v2.1 < *","simatic_pcs_7_advanced_process_functions_v2.2 < *","simatic_pcs_7_advanced_process_graphics_v10.0 < *","simatic_pcs_7_advanced_process_graphics_v9.1 < *","simatic_pcs_7_advanced_process_library_incl._faceplates_v10.0 < *"],"published":"2025-08-12","updated":"2026-09-08","sourceUpdated":"2026-09-08T09:17:30.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-30033","references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-282044.html","label":"productcert@siemens.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2025-08-12T20:10:10.615077Z"},"epss":0.00206,"epssPercentile":0.10934,"ingestedAt":"2026-08-11T16:47:03.691Z","slug":"CVE-2025-30033","body":"## Overview\n\nThe affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}