CVE-2025-40569 is a race condition vulnerability in the "Load Configuration from Local PC" function of the web interface for several Siemens RUGGEDCOM and SCALANCE industrial network devices. This flaw, affecting all versions prior to V3.2, could allow an authenticated remote attacker to load a malicious configuration onto the device. While requiring a legitimate administrator to initiate the function and the attacker to win a race condition, successful exploitation could lead to high integrity impact, though confidentiality and availability are not affected. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | RUGGEDCOM RST2428P | >= 0, < V3.2CNA affecteddefault unknown | |
| Siemens | SCALANCE XCH328 | >= 0, < V3.2CNA affecteddefault unknown | |
| Siemens | SCALANCE XCM324 | >= 0, < V3.2CNA affecteddefault unknown | |
| Siemens | SCALANCE XCM328 | >= 0, < V3.2CNA affecteddefault unknown | |
| Siemens | SCALANCE XCM332 | >= 0, < V3.2CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.