CVE-2025-40742
Summary
| CVE | CVE-2025-40742 |
|---|---|
| State | PUBLISHED |
| Assigner | siemens |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-07-08 11:15:30 UTC |
| Updated | 2026-05-12 10:16:41 UTC |
| Description | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V11.0), SIPROTEC 5 6MD89 (CP300) (All versions < V11.0), SIPROTEC 5 6MD89 (CP300) V9.6x (All versions < V11.0), SIPROTEC 5 6MU85 (CP300) (All versions < V11.0), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions < V11.0), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions < V11.0), SIPROTEC 5 7SA84 (CP200) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions < V11.0), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions < V11.0), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions < V11.0), SIPROTEC 5 7SD84 (CP200) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions < V11.0), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions < V11.0), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions < V11.0), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions < V11.0), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions < V11.0), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions < V11.0), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions < V11.0), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions < V11.0), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions < V11.0), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions < V11.0), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions < V11.0), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions < V11.0), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions < V11.0), SIPROTEC 5 7ST86 (CP300) (All versions < V11.0), SIPROTEC 5 7SX82 (CP150) (All versions < V11.0), SIPROTEC 5 7SX85 (CP300) (All versions < V11.0), SIPROTEC 5 7SY82 (CP150) (All versions < V11.0), SIPROTEC 5 7UM85 (CP300) (All versions < V11.0), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions < V11.0), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions < V11.0), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions < V11.0), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions < V11.0), SIPROTEC 5 7VE85 (CP300) (All versions < V11.0), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions < V11.0), SIPROTEC 5 7VU85 (CP300) (All versions < V11.0), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V11.0). The affected devices include session identifiers in URL requests for certain functionalities. This could allow an attacker to retrieve sensitive session data from browser history, logs, or other storage mechanisms, potentially leading to unauthorized access. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002740000 probability, percentile 0.508770000 (date 2026-05-12)
Problem Types: CWE-598 | CWE-598 CWE-598: Use of GET Request Method With Sensitive Query Strings
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighAttack Requirements
NonePrivileges Required
NoneUser Interaction
PassiveConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Siemens | SIPROTEC 5 6MD84 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD89 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MD89 CP300 V9.6x | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 6MU85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7KE85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7KE85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA84 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA87 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SA87 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD84 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD87 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SD87 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ81 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ81 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SJ86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SK82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SK82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SK85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SK85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL87 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SL87 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SS85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SS85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7ST85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7ST85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7ST86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SX82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SX85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7SY82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UM85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT82 CP100 | affected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT82 CP150 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT85 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT86 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT86 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT87 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7UT87 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7VE85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7VK87 CP200 | unaffected * custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7VK87 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 7VU85 CP300 | affected V11.0 custom | Not specified |
| CNA | Siemens | SIPROTEC 5 Compact 7SX800 CP050 | affected V11.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/html/ssa-904646.html | [email protected] | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.