---
id: CVE-2025-30033
title: The affected setup component is vulnerable to DLL hijacking
summary: >-
  The affected setup component is vulnerable to DLL hijacking. This could allow
  an attacker to execute arbitrary code when a legitimate user installs an
  application that uses the affected setup component.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: Siemens
product: Automation License Manager V6.0
affected:
  - automation_license_manager_v6.0 < *
  - automation_license_manager_v6.2 < V6.2 Upd3
  - cemat_v10.0 < *
  - cp_ptp_param_configuring_interface < *
  - create_myconfig_cmc < V6.9
  - energy_support_library_ensl < *
  - fm_configuration_package < *
  - modular_pid_ctrl_tool < *
  - multifieldbus_configuration_tool_mfct < V1.5.5.0
  - openpcs_7_v10.0 < *
  - openpcs_7_v9.1 < *
  - network_planner_sinetplan < V2.0 SP2
  - simatic_automation_tool < V5.0 SP4
  - simatic_automation_tool_sdk_windows < V5.0 SP4
  - simatic_batch_v10.0 < *
  - simatic_batch_v9.1 < *
  - simatic_control_function_library_cfl_v1.x < *
  - simatic_control_function_library_cfl_v2.x < *
  - simatic_control_function_library_cfl_v3.x < V3.1.0.2
  - simatic_control_function_library_cfl_v4.x < V4.1
  - simatic_d7-sys < V10.0 SP1
  - simatic_easie_core_package < *
  - simatic_easie_document_skills < *
  - simatic_easie_pcs_7_skill_package < *
  - simatic_easie_workflow_skills < *
  - simatic_energy_suite_v17 < *
  - simatic_energy_suite_v18 < *
  - simatic_energy_suite_v19 < V19 Update 4
  - simatic_logon_v1.6 < *
  - simatic_logon_v2.0 < V2.0 Upd3
  - simatic_management_agent < V9.1 SP1 Upd8
  - simatic_management_console < V9.1 SP1 Upd8
  - simatic_mtp_creator_v2.x < V2.1
  - simatic_mtp_creator_v3.x < *
  - simatic_mtp_creator_v4.x < V4.1.0.1
  - simatic_mtp_creator_v5.x < V5.0.0.1
  - simatic_mtp_integrator_v1.x < *
  - simatic_mtp_integrator_v2.x < *
  - simatic_net_pc_software_v16 < *
  - simatic_net_pc_software_v17 < *
  - simatic_net_pc_software_v18 < *
  - simatic_net_pc_software_v19 < *
  - simatic_net_pc_software_v20 < V20.0 Update 1
  - simatic_odk_1500s < *
  - simatic_pcs_7_advanced_process_faceplates_v9.1 < V9.1 SP2 Upd4
  - simatic_pcs_7_advanced_process_functions_v2.1 < *
  - simatic_pcs_7_advanced_process_functions_v2.2 < *
  - simatic_pcs_7_advanced_process_graphics_v10.0 < *
  - simatic_pcs_7_advanced_process_graphics_v9.1 < *
  - simatic_pcs_7_advanced_process_library_incl._faceplates_v10.0 < *
published: '2025-08-12'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:17:30.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30033'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-282044.html'
    label: productcert@siemens.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-08-12T20:10:10.615077Z'
epss: 0.00206
epssPercentile: 0.09342
ingestedAt: '2026-08-11T16:47:03.691Z'
---

## Overview

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
