Password Exposure Vulnerability in SiPass Integrated by Siemens
CVE-2025-40774

6.7MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
14 October 2025

What is CVE-2025-40774?

A vulnerability has been identified in SiPass Integrated prior to version 3.0 that permits the storage of user passwords in an encrypted format. However, due to the design flaw, decryption keys are accessible to users with administrative privileges. This scenario creates a risk where unauthorized individuals can potentially recover and exploit user passwords, leading to unauthorized access, data breaches, and a compromise of the system integrity.

Affected Version(s)

SiPass integrated 0

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40774 : Password Exposure Vulnerability in SiPass Integrated by Siemens