Network Share Authentication Flaw in Siemens SIMATIC Virtualization as a Service
CVE-2025-40804

9.3CRITICAL

Key Information:

Vendor

Siemens

Vendor
CVE Published:
9 September 2025

What is CVE-2025-40804?

A critical flaw has been discovered in the Siemens SIMATIC Virtualization as a Service (SIVaaS) that allows unauthorized access to a network share without authentication. This vulnerability enables potential attackers to view, access, or modify sensitive information stored on the service, posing significant risks to the integrity and confidentiality of the data. Organizations utilizing this application must implement immediate security measures to protect against unauthorized exploitation.

Affected Version(s)

SIMATIC Virtualization as a Service (SIVaaS) 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40804 : Network Share Authentication Flaw in Siemens SIMATIC Virtualization as a Service