---
id: CVE-2025-40818
title: >-
  A vulnerability has been identified in SINEMA Remote Connect Server (All
  versions < V3.2 SP4)
summary: >-
  A vulnerability has been identified in SINEMA Remote Connect Server (All
  versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on
  the server that are not properly protected allowing any user with server
  access to read …
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-732
vendor: siemens
product: sinema_remote_connect_server
affected:
  - sinema_remote_connect_server < 3.2
  - sinema_remote_connect_server = 3.2
patched:
  - sinema_remote_connect_server 3.2
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40818'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-626856.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00102
epssPercentile: 0.00854
ingestedAt: '2026-10-07T20:46:46.790Z'
---

## Overview

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server potentially enabling man-in-the-middle, traffic decryption or unauthorized access to services that trust these certificates.

## Affected

- `sinema_remote_connect_server < 3.2`
- `sinema_remote_connect_server = 3.2`

## Remediation

Upgrade past the affected range:

- `sinema_remote_connect_server 3.2`
