CVE-2025-40805 PUBLISHED CVSS 10 CRITICAL

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

EPSS 0.08% · 24.4th percentile

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.08%
24.4th percentile

Affected Products

VendorProductVersions
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design0
SiemensIndustrial Edge Device Kit - arm64 V1.100
SiemensIndustrial Edge Device Kit - x86-64 V1.160
SiemensSIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom)0
SiemensSIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top)0
SiemensSIMATIC IPC BX-59A Industrial Edge Device0
SiemensSIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit0
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel0
SiemensSIMATIC IPC427E Industrial Edge Device0
SiemensIndustrial Edge Device Kit - arm64 V1.120
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel hygienic0
SiemensSIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top)0
SiemensSIMATIC HMI MTP2200 Unified Comfort Panel neutral design0
SiemensIndustrial Edge Device Kit - arm64 V1.80
SiemensIndustrial Edge Device Kit - arm64 V1.210
SiemensSIMATIC IPC BX-39A Industrial Edge Device0
SiemensIndustrial Edge Device Kit - arm64 V1.50
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel0
SiemensSIPLUS HMI MTP1200 Unified Comfort0
SiemensIndustrial Edge Device Kit - arm64 V1.250

…and 87 more

Timeline

References

Open in Interactive Console →