Plain Text Password Vulnerability in Siemens Power Meters
CVE-2025-40752

6.8MEDIUM

What is CVE-2025-40752?

A security issue has been identified in specific models of Siemens POWER METER SICAM Q100 and Q200 devices where the SMTP account password is stored in plain text. This vulnerability enables an authenticated local attacker to access the password and exploit the SMTP service for unauthorized purposes, potentially leading to significant security risks for the affected systems.

Affected Version(s)

POWER METER SICAM Q100 V2.60

POWER METER SICAM Q100 V2.60

POWER METER SICAM Q100 V2.60

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.