Denial-of-Service Vulnerability in SINEC Traffic Analyzer by Siemens
CVE-2025-40766

6.8MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
12 August 2025

What is CVE-2025-40766?

A vulnerability exists in the SINEC Traffic Analyzer, wherein the application operates Docker containers without sufficient resource and security restrictions. This oversight could enable malicious actors to execute denial-of-service (DoS) attacks, potentially disrupting the affected service and impacting network operations. It is crucial for users of version 3.0 and below to assess their security posture and apply necessary mitigations to thwart potential exploitation.

Affected Version(s)

SINEC Traffic Analyzer 0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40766 : Denial-of-Service Vulnerability in SINEC Traffic Analyzer by Siemens