← Back

CVE-2025-40819

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: productcert@siemens.com (Secondary)

Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.

Affected (4)

1 product
Sinema Remote Connect Server
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Before 3.2
Version 3.2 sp1
Version 3.2 sp2
Version 3.2 sp3

References (1)

Source: productcert@siemens.com
Vendor Advisory

Timeline

No history available yet.