CVE-2025-40804: Critical severity Siemens SIMATIC Virtualization as a Service vulnerability
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40804?
CVE-2025-40804 is considered a critical vulnerability due to its ability to expose sensitive data without authentication.
How can I fix CVE-2025-40804?
To fix CVE-2025-40804, ensure that network shares in SIMATIC Virtualization as a Service are properly secured with authentication measures.
What are the potential impacts of CVE-2025-40804?
CVE-2025-40804 may allow attackers to access or alter sensitive data, leading to data breaches or unauthorized modifications.
Which software is affected by CVE-2025-40804?
CVE-2025-40804 affects all versions of Siemens SIMATIC Virtualization as a Service.
Is authentication required to exploit CVE-2025-40804?
No, CVE-2025-40804 allows exploitation without any authentication, making it particularly dangerous.