CVE-2025-40805
Unknown
Unknown - Not Provided
Authentication Bypass in Siemens API Enables Remote User Impersonation
Publication date: 2026-01-13
Last updated on: 2026-01-13
Assigner: Siemens AG
Description
Description
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | industrial_edge_device_kit | From 1.5 (inc) to 1.23 (inc) |
| siemens | simatic_hmi_unified_comfort_panels | to 21 (exc) |
| siemens | simatic_automation_workstations | * |
| siemens | simatic_hmi_unified_comfort_panels | 21 |
| siemens | simatic_hmi_unified_comfort_panels | 21.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |