Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.
History

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens industrial Edge Cloud Device (iecd)
Siemens industrial Edge Device Kit
Siemens industrial Edge Own Device (ieod)
Siemens industrial Edge Virtual Device (ievd)
Siemens scalance Lpe9413
Siemens scalance Lpe9433
Siemens simatic Automation Workstation
Siemens simatic Hmi Mtp1000
Siemens simatic Hmi Mtp1200
Siemens simatic Hmi Mtp1500
Siemens simatic Hmi Mtp1900
Siemens simatic Hmi Mtp2200
Siemens simatic Hmi Mtp700
Siemens simatic Iot2050
Siemens simatic Ipc127e
Siemens simatic Ipc227e
Siemens simatic Ipc227g
Siemens simatic Ipc427e
Siemens simatic Ipc847e
Siemens simatic Ipc Bx-39a
Siemens simatic Ipc Bx-59a
Siemens siplus Hmi Mtp1000
Siemens siplus Hmi Mtp1200
Siemens siplus Hmi Mtp700
Vendors & Products Siemens
Siemens industrial Edge Cloud Device (iecd)
Siemens industrial Edge Device Kit
Siemens industrial Edge Own Device (ieod)
Siemens industrial Edge Virtual Device (ievd)
Siemens scalance Lpe9413
Siemens scalance Lpe9433
Siemens simatic Automation Workstation
Siemens simatic Hmi Mtp1000
Siemens simatic Hmi Mtp1200
Siemens simatic Hmi Mtp1500
Siemens simatic Hmi Mtp1900
Siemens simatic Hmi Mtp2200
Siemens simatic Hmi Mtp700
Siemens simatic Iot2050
Siemens simatic Ipc127e
Siemens simatic Ipc227e
Siemens simatic Ipc227g
Siemens simatic Ipc427e
Siemens simatic Ipc847e
Siemens simatic Ipc Bx-39a
Siemens simatic Ipc Bx-59a
Siemens siplus Hmi Mtp1000
Siemens siplus Hmi Mtp1200
Siemens siplus Hmi Mtp700

Tue, 13 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
Description Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2026-01-13T09:44:03.338Z

Updated: 2026-01-13T17:37:40.414Z

Reserved: 2025-04-16T08:50:26.973Z

Link: CVE-2025-40805

cve-icon Vulnrichment

Updated: 2026-01-13T17:37:37.176Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T10:15:58.047

Modified: 2026-01-13T14:03:18.990

Link: CVE-2025-40805

cve-icon Redhat

No data.