CVE Database
/

CVE-2025-40743

Back to search

CVE-2025-40743

Published: Aug 12, 2025

Modified: Aug 13, 2025

PUBLISHED

CVSS v3.1

8.3

HIGH

Description

A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK 840D sl (All versions < V4.95 SP5), SINUMERIK MC (All versions < V1.25 SP1), SINUMERIK MC V1.15 (All versions < V1.15 SP5), SINUMERIK ONE (All versions < V6.25 SP1), SINUMERIK ONE V6.15 (All versions < V6.15 SP5). The affected application improperly validates authentication for its VNC access service, allowing access with insufficient password verification. This could allow an attacker to gain unauthorized remote access and potentially compromise system confidentiality, integrity, or availability.

VendorProductVersions

Siemens

SINUMERIK 828D PPU.4

affected
0 - < V4.95 SP5

Siemens

SINUMERIK 828D PPU.5

affected
0 - < V5.25 SP1

Siemens

SINUMERIK 840D sl

affected
0 - < V4.95 SP5

Siemens

SINUMERIK MC

affected
0 - < V1.25 SP1

Siemens

SINUMERIK MC V1.15

affected
0 - < V1.15 SP5

Siemens

SINUMERIK ONE

affected
0 - < V6.25 SP1

Siemens

SINUMERIK ONE V6.15

affected
0 - < V6.15 SP5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now