{"id":"CVE-2025-40773","title":"A vulnerability has been identified in SiPass integrated (All versions < V3.0)","summary":"A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an att…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-639"],"vendor":"siemens","product":"sipass_integrated","affected":["sipass_integrated < 3.00"],"patched":["sipass_integrated 3.00"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40773","references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-599451.html","label":"productcert@siemens.com"}],"tags":["nvd"],"epss":0.00196,"epssPercentile":0.08458,"ingestedAt":"2026-10-08T11:31:27.375Z","slug":"CVE-2025-40773","body":"## Overview\n\nA vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request.\r\n\r\nSuccessful exploitation allows an attacker to potentially manipulate data belonging to other users.\n\n## Affected\n\n- `sipass_integrated < 3.00`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sipass_integrated 3.00`","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}