A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* |
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec Security Monitor |
|
| Vendors & Products |
Siemens
Siemens sinec Security Monitor |
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-12-09T10:44:33.449Z
Updated: 2025-12-09T15:37:58.195Z
Reserved: 2025-04-16T08:50:26.976Z
Link: CVE-2025-40831
Updated: 2025-12-09T15:37:54.559Z
Status : Analyzed
Published: 2025-12-09T16:17:46.893
Modified: 2025-12-10T21:38:30.183
Link: CVE-2025-40831
No data.