CVE-2025-40818Low· 3.3▾ SunlitA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.
sinema_remote_connect_server < 3.2sinema_remote_connect_server = 3.2Upgrade past the affected range:
sinema_remote_connect_server 3.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-40819Medium· 4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4)
CVE-2025-43470Medium· 5.5A permissions issue was addressed with additional restrictions
CVE-2026-10840High· 7.1A flaw was found in the OpenShift Pipelines operator
CVE-2026-0775High· 7.0npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
CVE-2025-40829High· 7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512)
CVE-2025-40941Medium· 4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)