PT-2025-36679 · Siemens · Sinamics S210+2
Published
2025-09-09
·
Updated
2025-09-09
·
CVE-2025-40594
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SINAMICS G220 versions prior to 6.4 HF2
SINAMICS S200 version 6.4
SINAMICS S210 versions prior to 6.4 HF2
Description:
The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management and manipulation of configuration data resulting from leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.
Recommendations:
Update SINAMICS G220 to version 6.4 HF2 or later.
Update SINAMICS S210 to version 6.4 HF2 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinamics G220
Sinamics S200
Sinamics S210