CVE-2025-39205: High severity Siemens MicroSCADA X SYS600 vulnerability
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39205?
CVE-2025-39205 is considered a high-severity vulnerability due to its potential for remote exploitation via Man-in-the-Middle attacks.
How do I fix CVE-2025-39205?
To mitigate CVE-2025-39205, ensure proper certificate validation is implemented in the TLS protocol within Siemens MicroSCADA X SYS600.
Who is affected by CVE-2025-39205?
The vulnerability affects users of the Siemens MicroSCADA X SYS600 product that utilize the IEC 61850 protocol.
What type of attack does CVE-2025-39205 allow?
CVE-2025-39205 allows remote Man-in-the-Middle attacks due to inadequate TLS certificate validation.
Is CVE-2025-39205 being actively exploited?
As of now, there are no reported active exploitation attempts for CVE-2025-39205, but it poses a significant risk.