A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27242 A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 20 Oct 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens sinamics G220 Firmware
Siemens sinamics S200 Firmware
Siemens sinamics S210 Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:siemens:sinamics_g220:-:-:*:*:*:*:*:*
cpe:2.3:h:siemens:sinamics_s200:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinamics_s210:-:-:*:*:*:*:*:*
cpe:2.3:o:siemens:sinamics_g220_firmware:6.4:-:*:*:*:*:*:*
cpe:2.3:o:siemens:sinamics_g220_firmware:6.4:hf1:*:*:*:*:*:*
cpe:2.3:o:siemens:sinamics_s200_firmware:6.4:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sinamics_s210_firmware:6.4:-:*:*:*:*:*:*
cpe:2.3:o:siemens:sinamics_s210_firmware:6.4:hf1:*:*:*:*:*:*
Vendors & Products Siemens sinamics G220 Firmware
Siemens sinamics S200 Firmware
Siemens sinamics S210 Firmware

Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinamics G220
Siemens sinamics S200
Siemens sinamics S210
Vendors & Products Siemens
Siemens sinamics G220
Siemens sinamics S200
Siemens sinamics S210

Tue, 09 Sep 2025 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-09-09T19:36:11.082Z

Reserved: 2025-04-16T08:20:17.034Z

Link: CVE-2025-40594

cve-icon Vulnrichment

Updated: 2025-09-09T19:36:06.833Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T09:15:36.743

Modified: 2025-10-20T19:20:29.113

Link: CVE-2025-40594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-09T21:31:40Z