#VU111076 Incorrect default permissions in Energy Services - CVE-2025-40585

 

#VU111076 Incorrect default permissions in Energy Services - CVE-2025-40585

Published: June 11, 2025


Vulnerability identifier: #VU111076
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-40585
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Energy Services
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to incorrect default permissions within G5DFR. A remote attacker can gain control of G5DFR component and tamper with outputs from the device.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links