VDB
GCVE-110-NCSC-2025-106
GCVE-110-NCSC-2025-106
Advisory PublishedCVSS 7.3/10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Weaknesses (CWE)
CWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-287Improper AuthenticationCWE-404Improper Resource Shutdown or ReleaseCWE-20Improper Input ValidationCWE-325Missing Cryptographic StepCWE-754Improper Check for Unusual or Exceptional ConditionsCWE-122Heap-based Buffer OverflowCWE-420Unprotected Alternate ChannelCWE-416Use After FreeCWE-476NULL Pointer DereferenceCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-787Out-of-bounds WriteCWE-400Uncontrolled Resource ConsumptionCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-306Missing Authentication for Critical FunctionCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-798Use of Hard-coded CredentialsCWE-352Cross-Site Request Forgery (CSRF)CWE-620Unverified Password ChangeCWE-1390Weak AuthenticationCWE-204Observable Response DiscrepancyCWE-653Improper Isolation or CompartmentalizationCWE-269Improper Privilege ManagementCWE-295Improper Certificate Validation
Risk Scores
CVSS 3.1
7.3/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Siemens | vers:unknown/>=3|<312 | — | — |
| Siemens | vers:siemens/2.0 sp1 | — | — |
| Siemens | vers:siemens/v224.0 update 12 | — | — |
| Siemens | vers:unknown/<v9.24.34 | — | — |
| Siemens | vers:unknown/none | — | — |
| Siemens | vers:unknown/4.2 | — | — |
| Siemens | vers:unknown/<v10.21.0 | — | — |
| Siemens | vers:unknown/<v225.0update3 | — | — |
| Siemens | vers:unknown/<v8.3 | — | — |
| Siemens | vers:unknown/4.0 | — | — |
| Siemens | vers:siemens/225.0 update 3 | — | — |
| Siemens | vers:unknown/<v1.21.1-1 | — | — |
| Siemens | vers:unknown/<v4.3 | — | — |
| Siemens | vers:unknown/<v1.21.1-1-a | — | — |
| Siemens | vers:siemens/224.0 update 12 | — | — |
| Siemens | vers:unknown/<v1.3 | — | — |
| Siemens | vers:unknown/<v2.0 | — | — |
| Siemens | vers:unknown/4.1 | — | — |
| Siemens | vers:unknown/<v2.0.0 | — | — |
| Siemens | vers:unknown/<v224.0update12 | — | — |
| Siemens | vers:unknown/<v1.20.2-1 | — | — |
| Siemens | vers:unknown/10.16.0 | — | — |
| Siemens | vers:unknown/<* | — | — |
Aliases
CVE-2022-21658CVE-2023-2975CVE-2023-3446CVE-2023-3817CVE-2023-4807CVE-2023-5363CVE-2023-5678CVE-2023-7104CVE-2024-0056CVE-2024-0232CVE-2024-0727CVE-2024-21319CVE-2024-23814CVE-2024-30105CVE-2024-41788CVE-2024-41789CVE-2024-41790CVE-2024-41791CVE-2024-41792CVE-2024-41793CVE-2024-41794CVE-2024-41795CVE-2024-41796CVE-2024-54091CVE-2024-54092CVE-2024-5535CVE-2024-9143CVE-2025-1097CVE-2025-1098CVE-2025-1974CVE-2025-24513CVE-2025-24514CVE-2025-29999CVE-2025-30000CVE-2025-30280
References
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.