Логотип exploitDog
bind:CVE-2025-40594
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-40594

Количество 3

Количество 3

nvd логотип

CVE-2025-40594

5 месяцев назад

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-jg6x-p73x-m4hc

5 месяцев назад

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

CVSS3: 6.3
EPSS: Низкий
fstec логотип

BDU:2025-14337

5 месяцев назад

Уязвимость программно-аппаратного обеспечения Siemens, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-40594

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-jg6x-p73x-m4hc

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-14337

Уязвимость программно-аппаратного обеспечения Siemens, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу