VDB
GCVE-110-NCSC-2025-187
GCVE-110-NCSC-2025-187
Advisory PublishedCVSS 7.8/10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses (CWE)
CWE-311Missing Encryption of Sensitive DataCWE-125Out-of-bounds ReadCWE-416Use After FreeCWE-122Heap-based Buffer OverflowCWE-325Missing Cryptographic StepCWE-190Integer Overflow or WraparoundCWE-73External Control of File Name or PathCWE-400Uncontrolled Resource ConsumptionCWE-201Insertion of Sensitive Information Into Sent DataCWE-222Truncation of Security-relevant InformationCWE-304Missing Critical Step in AuthenticationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-20Improper Input ValidationCWE-787Out-of-bounds WriteCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-404Improper Resource Shutdown or ReleaseCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-476NULL Pointer DereferenceCWE-268Privilege ChainingCWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-703Improper Check or Handling of Exceptional ConditionsCWE-466Return of Pointer Value Outside of Expected RangeCWE-940Improper Verification of Source of a Communication ChannelCWE-130Improper Handling of Length Parameter InconsistencyCWE-269Improper Privilege ManagementCWE-667Improper LockingCWE-129Improper Validation of Array IndexCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-911Improper Update of Reference CountCWE-770Allocation of Resources Without Limits or ThrottlingCWE-332Insufficient Entropy in PRNGCWE-371-CWE-665Improper InitializationCWE-121Stack-based Buffer OverflowCWE-310-CWE-366Race Condition within a ThreadCWE-863Incorrect AuthorizationCWE-276Incorrect Default Permissions
Risk Scores
CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Siemens | vers:siemens/7.4.3 | — | — |
| Siemens | vers:unknown/<v1.3.0 | — | — |
| Siemens | vers:all/<v3.2 | — | — |
| Siemens | vers:unknown/none | — | — |
| Siemens | vers:siemens/3.1.0 | — | — |
| Siemens | vers:all/>=v3.1.0 | — | — |
| Siemens | vers:unknown/1.0 | — | — |
| Siemens | vers:all/<v2404.0013 | — | — |
| Siemens | vers:all/* | — | — |
| Siemens | vers:all/<v3.1 | — | — |
| Siemens | vers:unknown/* | — | — |
| Siemens | vers:siemens/3.0.0 | — | — |
| Siemens | vers:unknown/<v1.1 | — | — |
Aliases
CVE-2021-41617CVE-2023-28531CVE-2023-38545CVE-2023-38546CVE-2023-44487CVE-2023-4527CVE-2023-46218CVE-2023-46219CVE-2023-4806CVE-2023-48795CVE-2023-4911CVE-2023-51384CVE-2023-51385CVE-2023-52927CVE-2023-5363CVE-2023-6246CVE-2023-6779CVE-2023-6780CVE-2024-12133CVE-2024-12243CVE-2024-24855CVE-2024-26596CVE-2024-28085CVE-2024-2961CVE-2024-33599CVE-2024-33600CVE-2024-33601CVE-2024-33602CVE-2024-34397CVE-2024-37370CVE-2024-37371CVE-2024-41797CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-50246CVE-2024-53166CVE-2024-57977CVE-2024-57996CVE-2024-58005CVE-2024-6119CVE-2024-6387CVE-2025-0133CVE-2025-21701CVE-2025-21702CVE-2025-21712CVE-2025-21724CVE-2025-21728CVE-2025-21745CVE-2025-21756CVE-2025-21758CVE-2025-21765CVE-2025-21766CVE-2025-21767CVE-2025-21795CVE-2025-21796CVE-2025-21848CVE-2025-21862CVE-2025-21864CVE-2025-21865CVE-2025-26465CVE-2025-31115CVE-2025-32454CVE-2025-40567CVE-2025-40568CVE-2025-40569CVE-2025-40585CVE-2025-4373CVE-2025-4598CVE-2025-46836
References
Browse GCVE Records
74,585 records in the GCVE database · Updated July 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.