---
id: CVE-2025-40772
title: A vulnerability has been identified in SiPass integrated (All versions < V3.0)
summary: >-
  A vulnerability has been identified in SiPass integrated (All versions <
  V3.0). Affected server applications are vulnerable to stored Cross-Site
  Scripting (XSS), allowing an attacker to inject malicious code that can be
  executed by other…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: siemens
product: sipass_integrated
affected:
  - sipass_integrated < 3.00
patched:
  - sipass_integrated 3.00
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40772'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-599451.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00322
epssPercentile: 0.23178
ingestedAt: '2026-10-08T11:31:27.374Z'
---

## Overview

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page.

Successful exploitation allows an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation.

## Affected

- `sipass_integrated < 3.00`

## Remediation

Upgrade past the affected range:

- `sipass_integrated 3.00`
