3.5
/ 10
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request.
Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
Basic Information
ID
CVE-2025-40773
Source
siemens
Published
Oct 14, 2025 at 09:15
Affected Product
Vendor
Siemens
Product
SiPass integrated
Affected Versions
Siemens SiPass integrated 0