CVE-2025-40753: Medium severity Siemens POWER METER SICAM Q100 vulnerability
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q200 family (All versions >= V2.70 < V2.80). Affected devices export the password for the SMTP account as plain text in the Configuration File. This could allow an authenticated local attacker to extract it and use the configured SMTP service for arbitrary purposes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40753?
The severity of CVE-2025-40753 is classified as high due to potential unauthorized access to sensitive data.
How do I fix CVE-2025-40753?
To fix CVE-2025-40753, update the Siemens POWER METER SICAM Q100 to version 2.62 or higher.
What versions are affected by CVE-2025-40753?
CVE-2025-40753 affects all versions of Siemens POWER METER SICAM Q100 from 2.60 up to but not including 2.62.
Which products does CVE-2025-40753 affect?
CVE-2025-40753 specifically affects the Siemens POWER METER SICAM Q100 device.
Is there a workaround for CVE-2025-40753?
Currently, there are no documented workarounds for CVE-2025-40753; updating the software is recommended.