CVE-2025-40804: Siemens SIMATIC Virtualization As A Service Sivaas

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.

Affected products

  • Siemens SIMATIC Virtualization As A Service Sivaas: any version

Published 2025-09-09. Last modified 2026-06-17.