Unauthorized Access Vulnerability in Siemens Products
CVE-2025-40805

10CRITICAL

What is CVE-2025-40805?

A security vulnerability has been identified in specific Siemens devices that fail to properly enforce user authentication on certain API endpoints. This flaw could allow an attacker, who has identified the credentials of a legitimate user, to bypass authentication controls and impersonate that user, potentially leading to unauthorized actions within the system. Organizations using affected Siemens products should review their security postures and take appropriate actions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Industrial Edge Cloud Device (IECD) 0

Industrial Edge Device Kit - arm64 V1.10 0

Industrial Edge Device Kit - arm64 V1.11 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.