CVE detail
CVE-2025-40818 — CVE-2025-40818
Published 2025-12-09 · Modified 2026-06-17 · Vendor siemens · Product sinema_remote_connect_server · Source nvd
LOW
severity
CVSS-derived band
0.0010
EPSS probability
exploitation probability, 30d
1.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References