CVE-2025-40804: Siemens SIMATIC Virtualization As A Service Sivaas
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.
Affected products
- Siemens SIMATIC Virtualization As A Service Sivaas: any version
Published 2025-09-09. Last modified 2026-06-17.