CVE-2025-40774Medium· 4.4▾ SunlitA vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords.
Successful exploitation of this vulnerability allows an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.
sipass_integrated < 3.00Upgrade past the affected range:
sipass_integrated 3.00Connected by shared product, vendor, weakness, or advisory.
CVE-2025-40773Low· 3.5A vulnerability has been identified in SiPass integrated (All versions < V3.0)
CVE-2025-40772High· 7.4A vulnerability has been identified in SiPass integrated (All versions < V3.0)
CVE-2025-40765Critical· 9.8A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3)
CVE-2025-40829High· 7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512)
CVE-2025-40941Medium· 4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40940Medium· 4.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)