Information disclosure in Siemens products - CVE-2025-40757
Published: September 16, 2025
Vulnerability identifier: #VU115227
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-40757
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can download encrypted .db file containing passwords.
Affected software
APOGEE PXC Series (BACnet)
APOGEE PXC Series (P2 Ethernet)
TALON TC Series
APOGEE PXC Series (P2 Ethernet)
TALON TC Series
How to mitigate CVE-2025-40757
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.