CVE-2025-40831: Input Validation
Published Dec 9, 2025
·Updated
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality.
Affected Software
2 affected components
Siemens SINEC Security Monitor<4.10.0
Siemens SINEC Security Monitor<4.10.0
Event History
Dec 9, 2025
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40831?
CVE-2025-40831 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-40831?
To mitigate CVE-2025-40831, update SINEC Security Monitor to version 4.10.0 or later.
3
Who is affected by CVE-2025-40831?
CVE-2025-40831 affects all versions of SINEC Security Monitor prior to version 4.10.0.
4
What type of attack can exploit CVE-2025-40831?
An attacker can exploit CVE-2025-40831 to trigger a denial of service condition.
5
What functionality is compromised in CVE-2025-40831?
CVE-2025-40831 compromises the input validation of the date parameter during report generation.