Default Credentials Flaw in G5DFR Component by Siemens
CVE-2025-40585

9.5CRITICAL

Key Information:

Vendor

Siemens

Vendor
CVE Published:
10 June 2025

What is CVE-2025-40585?

A security vulnerability has been detected in Siemens' Energy Services, specifically affecting all versions utilizing the G5DFR component. The issue arises from the presence of default credentials, which can potentially be exploited by unauthorized users. This risk allows malicious actors to gain control over the G5DFR component, leading to possible tampering with the outputs and functionality of the device. It is crucial for users of affected products to address this issue promptly to prevent unauthorized access and ensure operational integrity.

Affected Version(s)

Energy Services 0

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.