---
id: CVE-2025-40774
title: A vulnerability has been identified in SiPass integrated (All versions < V3.0)
summary: >-
  A vulnerability has been identified in SiPass integrated (All versions <
  V3.0). Affected server applications store user passwords encrypted in its
  database. Decryption keys are accessible to users with administrative
  privileges, allowing…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-257
vendor: siemens
product: sipass_integrated
affected:
  - sipass_integrated < 3.00
patched:
  - sipass_integrated 3.00
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40774'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-599451.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00136
epssPercentile: 0.02635
ingestedAt: '2026-10-08T11:31:27.375Z'
---

## Overview

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords.

Successful exploitation of this vulnerability allows an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.

## Affected

- `sipass_integrated < 3.00`

## Remediation

Upgrade past the affected range:

- `sipass_integrated 3.00`
