CVE 6.2 MEDIUM

CVE-2025-40752_CVE-2025-40752

6.2 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q200 family (All versions >= V2.70 < V2.80). Affected devices store the password for the SMTP account as plain text. This could allow an authenticated local attacker to extract it and use the configured SMTP service for arbitrary purposes.

Basic Information

ID CVE-2025-40752
Source siemens
Published Aug 12, 2025 at 11:17

Affected Product

Vendor Siemens
Product POWER METER SICAM Q100
Version V2.60
Affected Versions Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q100 V2.60
Siemens POWER METER SICAM Q200 family V2.70

CWE Classification

AI Assessment

Vendor Siemens
Product POWER METER SICAM Q100, POWER METER SICAM Q200
Version V2.60-V2.61, V2.70-V2.79

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.