CVE-2025-40831: Siemens Sinec Security Monitor

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality.

Affected products

  • Siemens Sinec Security Monitor: before 4.10.0 (fixed in 4.10.0)

Published 2025-12-09. Last modified 2026-10-07.