CVE-2025-40766: Medium severity Siemens SINEC Traffic Analyzer vulnerability
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40766?
CVE-2025-40766 is classified as a denial-of-service vulnerability with potential for significant disruption.
How do I fix CVE-2025-40766?
To fix CVE-2025-40766, upgrade the SINEC Traffic Analyzer to version 3.0 or later and implement necessary resource and security limitations on Docker containers.
What products are affected by CVE-2025-40766?
CVE-2025-40766 affects all versions of SINEC Traffic Analyzer prior to version 3.0.
What type of attack can be executed due to CVE-2025-40766?
CVE-2025-40766 can allow an attacker to perform a denial-of-service (DoS) attack on the affected application.
Is there a workaround for CVE-2025-40766?
There are no documented workarounds for CVE-2025-40766; the best mitigation is to update to the latest version.