Vulnerability in POWER METER SICAM Q100 and Q200 by Siemens
CVE-2025-40753

6.8MEDIUM

What is CVE-2025-40753?

A vulnerability has been detected in Siemens' POWER METER SICAM Q100 and Q200 lines, where versions of the devices export SMTP account passwords in plain text within the configuration file. This flaw could grant an authenticated local attacker the ability to extract these credentials, utilizing the SMTP service for unauthorized activities, potentially compromising system integrity and security.

Affected Version(s)

POWER METER SICAM Q100 V2.60

POWER METER SICAM Q100 V2.60

POWER METER SICAM Q100 V2.60

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40753 : Vulnerability in POWER METER SICAM Q100 and Q200 by Siemens