CVE-2025-40818: Low severity Siemens SINEMA Remote Connect Server vulnerability
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40818?
CVE-2025-40818 is classified as a significant vulnerability due to the risk associated with exposing private SSL/TLS keys.
How do I fix CVE-2025-40818?
To mitigate CVE-2025-40818, update your Siemens SINEMA Remote Connect Server to version 3.2 SP4 or later.
What causes CVE-2025-40818?
CVE-2025-40818 is caused by improper protection of private SSL/TLS keys on the server, allowing unauthorized access.
Who is affected by CVE-2025-40818?
Organizations using any version of Siemens SINEMA Remote Connect Server prior to V3.2 SP4 are affected by CVE-2025-40818.
Can CVE-2025-40818 be exploited remotely?
CVE-2025-40818 requires authenticated access to the server, but could lead to significant security compromise if exploited.