VDB

GCVE-110-NCSC-2025-187

GCVE-110-NCSC-2025-187
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published June 10, 2025
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses (CWE)

CWE-311Missing Encryption of Sensitive DataCWE-125Out-of-bounds ReadCWE-416Use After FreeCWE-122Heap-based Buffer OverflowCWE-325Missing Cryptographic StepCWE-190Integer Overflow or WraparoundCWE-73External Control of File Name or PathCWE-400Uncontrolled Resource ConsumptionCWE-201Insertion of Sensitive Information Into Sent DataCWE-222Truncation of Security-relevant InformationCWE-304Missing Critical Step in AuthenticationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-20Improper Input ValidationCWE-787Out-of-bounds WriteCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-404Improper Resource Shutdown or ReleaseCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-476NULL Pointer DereferenceCWE-268Privilege ChainingCWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-703Improper Check or Handling of Exceptional ConditionsCWE-466Return of Pointer Value Outside of Expected RangeCWE-940Improper Verification of Source of a Communication ChannelCWE-130Improper Handling of Length Parameter InconsistencyCWE-269Improper Privilege ManagementCWE-667Improper LockingCWE-129Improper Validation of Array IndexCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-911Improper Update of Reference CountCWE-770Allocation of Resources Without Limits or ThrottlingCWE-332Insufficient Entropy in PRNGCWE-371-CWE-665Improper InitializationCWE-121Stack-based Buffer OverflowCWE-310-CWE-366Race Condition within a ThreadCWE-863Incorrect AuthorizationCWE-276Incorrect Default Permissions

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Siemensvers:siemens/7.4.3
Siemensvers:unknown/<v1.3.0
Siemensvers:all/<v3.2
Siemensvers:unknown/none
Siemensvers:siemens/3.1.0
Siemensvers:all/>=v3.1.0
Siemensvers:unknown/1.0
Siemensvers:all/<v2404.0013
Siemensvers:all/*
Siemensvers:all/<v3.1
Siemensvers:unknown/*
Siemensvers:siemens/3.0.0
Siemensvers:unknown/<v1.1

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,585 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›