← Back

CVE-2025-40594

nvd nist
Published: Sep 9, 2025Modified: Mar 10, 2026

JSON object

Loading...
6.9
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: productcert@siemens.com (Secondary)

Description

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

Affected (5)

3 products
Sinamics G220 Firmware
Sinamics S200 Firmware
Sinamics S210 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Version 6.4
Version 6.4 hf1
Running on/withPlatform Versions
Siemens
Sinamics G220
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.4
Running on/withPlatform Versions
Siemens
Sinamics S200
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Version 6.4
Version 6.4 hf1
Running on/withPlatform Versions
Siemens
Sinamics S210
All versions

References (1)

Source: productcert@siemens.com
Vendor Advisory

Timeline

No history available yet.