CVE 6.2 MEDIUM

CVE-2025-40753_CVE-2025-40753

6.2 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q200 family (All versions >= V2.70 < V2.80). Affected devices export the password for the SMTP account as plain text in the Configuration File. This could allow an authenticated local attacker to extract it and use the configured SMTP service for arbitrary purposes.

Basic Information

ID CVE-2025-40753
Source siemens
Published Aug 12, 2025 at 11:17

Affected Product

Vendor Siemens
Product POWER METER SICAM Q100
Version V2.60
Affected Versions Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q200 family V2.70

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.