PT-2025-28400 · Siemens · Siprotec 5 7Um85+16

Published

2025-07-08

·

Updated

2025-07-08

·

CVE-2025-40742

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SIPROTEC 5 6MD84 (CP300) (All versions) SIPROTEC 5 6MD85 (CP300) (All versions) SIPROTEC 5 6MD86 (CP300) (All versions) SIPROTEC 5 6MD89 (CP300) (All versions) SIPROTEC 5 6MD89 (CP300) V9.6 (All versions) SIPROTEC 5 6MU85 (CP300) (All versions) SIPROTEC 5 7KE85 (CP300) (All versions) SIPROTEC 5 7SA82 (CP100) (All versions) SIPROTEC 5 7SA82 (CP150) (All versions) SIPROTEC 5 7SA86 (CP300) (All versions) SIPROTEC 5 7SA87 (CP300) (All versions) SIPROTEC 5 7SD82 (CP100) (All versions) SIPROTEC 5 7SD82 (CP150) (All versions) SIPROTEC 5 7SD86 (CP300) (All versions) SIPROTEC 5 7SD87 (CP300) (All versions) SIPROTEC 5 7SJ81 (CP100) (All versions) SIPROTEC 5 7SJ81 (CP150) (All versions) SIPROTEC 5 7SJ82 (CP100) (All versions) SIPROTEC 5 7SJ82 (CP150) (All versions) SIPROTEC 5 7SJ85 (CP300) (All versions) SIPROTEC 5 7SJ86 (CP300) (All versions) SIPROTEC 5 7SK82 (CP100) (All versions) SIPROTEC 5 7SK82 (CP150) (All versions) SIPROTEC 5 7SK85 (CP300) (All versions) SIPROTEC 5 7SL82 (CP100) (All versions) SIPROTEC 5 7SL82 (CP150) (All versions) SIPROTEC 5 7SL86 (CP300) (All versions) SIPROTEC 5 7SL87 (CP300) (All versions) SIPROTEC 5 7SS85 (CP300) (All versions) SIPROTEC 5 7ST85 (CP300) (All versions) SIPROTEC 5 7ST86 (CP300) (All versions) SIPROTEC 5 7SX82 (CP150) (All versions) SIPROTEC 5 7SX85 (CP300) (All versions) SIPROTEC 5 7SY82 (CP150) (All versions) SIPROTEC 5 7UM85 (CP300) (All versions) SIPROTEC 5 7UT82 (CP100) (All versions) SIPROTEC 5 7UT82 (CP150) (All versions) SIPROTEC 5 7UT85 (CP300) (All versions) SIPROTEC 5 7UT86 (CP300) (All versions) SIPROTEC 5 7UT87 (CP300) (All versions) SIPROTEC 5 7VE85 (CP300) (All versions) SIPROTEC 5 7VK87 (CP300) (All versions) SIPROTEC 5 7VU85 (CP300) (All versions) SIPROTEC 5 Compact 7SX800 (CP050) (All versions)
Description: The affected devices include session identifiers in URL requests for certain functionalities. This could allow an attacker to retrieve sensitive session data from browser history, logs, or other storage mechanisms, potentially leading to unauthorized access.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-00190
CVE-2025-40742

Affected Products

Siprotec 5 6Md84
Siprotec 5 6Md85
Siprotec 5 6Md86
Siprotec 5 6Md89
Siprotec 5 7Ke85
Siprotec 5 7Sa82
Siprotec 5 7Sa86
Siprotec 5 7Sa87
Siprotec 5 7St86
Siprotec 5 7Sj81
Siprotec 5 7Sj85
Siprotec 5 7St85
Siprotec 5 7Um85
Siprotec 5 7Ut82
Siprotec 5 7Ut87
Siprotec 5 7Vk87
Siprotec 5 Compact 7Sx800