CVE-2025-40568
CVE-2025-40568
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 jun 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). An internal session termination functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to terminate legitimate users' sessions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Siemens · RUGGEDCOM RST2428PSiemens · SCALANCE XCH328Siemens · SCALANCE XCM324Siemens · SCALANCE XCM328Siemens · SCALANCE XCM332Siemens · SCALANCE XRH334 (24 V DC, 8xFO, CC)Siemens · SCALANCE XRM334 (230 V AC, 12xFO)Siemens · SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)Siemens · SCALANCE XRM334 (230 V AC, 8xFO)Siemens · SCALANCE XRM334 (24 V DC, 12xFO)Siemens · SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)Siemens · SCALANCE XRM334 (24 V DC, 8xFO)Siemens · SCALANCE XRM334 (2x230 V AC, 12xFO)Siemens · SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)Siemens · SCALANCE XRM334 (2x230 V AC, 8xFO)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →