---
id: CVE-2025-40831
title: >-
  A vulnerability has been identified in SINEC Security Monitor (All versions <
  V4.10.0)
summary: >-
  A vulnerability has been identified in SINEC Security Monitor (All versions <
  V4.10.0). The affected application lacks input validation of date parameter in
  report generation functionality. This could allow an authenticated, lowly
  privil…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: siemens
product: sinec_security_monitor
affected:
  - sinec_security_monitor < 4.10.0
patched:
  - sinec_security_monitor 4.10.0
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40831'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-882673.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00388
epssPercentile: 0.30638
ingestedAt: '2026-10-07T20:46:46.791Z'
---

## Overview

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality.

## Affected

- `sinec_security_monitor < 4.10.0`

## Remediation

Upgrade past the affected range:

- `sinec_security_monitor 4.10.0`
