CVE-2025-30033
The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.21%
- CWE
- CWE-427
- Published
- 2025-08-12
- Last modified
- 2026-09-08
Affected products
- Siemens Automation License Manager V6.0
- Siemens Automation License Manager V6.2
- Siemens CEMAT V10.0
- Siemens CP PtP Param configuring interface
- Siemens Create MyConfig (CMC)
- Siemens Energy Support Library (EnSL)
- Siemens FM Configuration Package
- Siemens Modular PID CTRL Tool
Weakness type
Related vulnerabilities
- CVE-2019-25268 — NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution
- CVE-2025-65118 — AVEVA Process Optimization Uncontrolled Search Path Element
- CVE-2025-13051 — Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges
- CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l
- CVE-2025-30248 — DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t
- CVE-2026-29610 — OpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH Handling
- CVE-2026-24502 — Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit
- CVE-2025-33208 — NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.