Description

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

INFO

Published Date :

2025-09-09T08:47:57.771Z

Last Modified :

2026-03-10T16:07:46.657Z

Source :

siemens
AFFECTED PRODUCTS

The following products are affected by CVE-2025-40594 vulnerability.

Vendors Products
Siemens
  • Sinamics G220
  • Sinamics G220 Firmware
  • Sinamics S200
  • Sinamics S200 Firmware
  • Sinamics S210
  • Sinamics S210 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-40594.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact