CVE-2025-40567
BaseFortify
Publication date: 2025-06-10
Last updated on: 2026-01-13
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the "Load Rollback" functionality of the web interface of certain Siemens RUGGEDCOM and SCALANCE devices with versions less than V3.2. It involves an incorrect authorization check that allows an authenticated remote attacker with a "guest" role to roll back configuration changes made by privileged users, potentially undoing important security or operational settings.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing a low-privileged authenticated user (guest role) to revert configuration changes made by administrators or other privileged users. This could disrupt network operations, reduce security by undoing protective configurations, and potentially lead to unauthorized control or instability in the affected devices.