CVE-2025-40773: Siemens Sipass Integrated
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
Affected products
- Siemens Sipass Integrated: before 3.00 (fixed in 3.00)
Published 2025-10-14. Last modified 2026-10-08.