ID

VAR-202509-0363


CVE

CVE-2025-40594


DESCRIPTION

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

Trust: 1.0

sources: NVD: CVE-2025-40594

AFFECTED PRODUCTS

vendor:siemensmodel:sinamics g220scope:eqversion:6.4

Trust: 1.0

vendor:siemensmodel:sinamics s210scope:eqversion:6.4

Trust: 1.0

vendor:siemensmodel:sinamics s200scope:eqversion:6.4

Trust: 1.0

sources: NVD: CVE-2025-40594

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-40594
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2025-40594
value: CRITICAL

Trust: 1.0

productcert@siemens.com: CVE-2025-40594
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 1.0
impactScore: 4.7
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2025-40594
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-40594 // NVD: CVE-2025-40594

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-269

Trust: 1.0

sources: NVD: CVE-2025-40594

EXTERNAL IDS

db:SIEMENSid:SSA-027652

Trust: 1.0

db:NVDid:CVE-2025-40594

Trust: 1.0

sources: NVD: CVE-2025-40594

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-027652.html

Trust: 1.0

sources: NVD: CVE-2025-40594

SOURCES

db:NVDid:CVE-2025-40594

LAST UPDATE DATE

2026-03-11T23:22:45.588000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-40594date:2026-03-10T18:17:54.193

SOURCES RELEASE DATE

db:NVDid:CVE-2025-40594date:2025-09-09T09:15:36.743