7.4
/ 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthorized scripts, potentially leading to cross-site scripting attacks.
AI Analysis
The vulnerability allows unsafe script execution methods due to an inadequate Content Security Policy, potentially leading to cross-site scripting attacks.
Basic Information
ID
CVE-2025-40769
Source
siemens
Published
Aug 12, 2025 at 11:17
Modified
Aug 12, 2025 at 13:36
Affected Product
Vendor
Siemens
Product
SINEC Traffic Analyzer
Affected Versions
Siemens SINEC Traffic Analyzer 0
CWE Classification
AI Assessment
AI Score
7.4 / 10
AI Severity
HIGH
Vendor
Siemens
Product
SINEC Traffic Analyzer
Version
All versions < V3.0