ICSA-25-289-06: Siemens SiPass Integrated
CISA advisory · released 2025-10-14
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 3, 2026-02-12 (final)
CISA's summary
Summary: SiPass integrated contains multiple vulnerabilities that could allow an unauthenticated remote attacker to exploit user accounts, manipulate data, impersonate users, or achieve arbitrary code execution on the SiPass integrated server. Siemens has released a new version for SiPass integrated and recommends to update to the latest version.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SiPass integrated | vers:intdot/<3.0 |
| Siemens | SiPass integrated V2.95 | vers:intdot/<2.95.3.23 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2023-35002 — CVE-2023-35002 · CWE-119
A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted, malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
- CVE-2025-40772 — CVE-2025-40772 · CWE-79
Affected server applications are vulnerable to stored cross-site scripting (XSS), which allows an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation enables an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation.
- CVE-2025-40773 — CVE-2025-40773 · CWE-639
Affected server applications contain a broken access control vulnerability. The authorization mechanisms lack sufficient server-side checks, which allows an attacker to execute specific API requests. Successful exploitation may allow an attacker to manipulate data belonging to other users.
- CVE-2025-40774 — CVE-2025-40774 · CWE-257
Affected server applications store user passwords in an encrypted format in their databases. Decryption keys are accessible to users with administrative privileges, which allows them to recover passwords. Successful exploitation of this vulnerability enables an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.
Acknowledgments, as the advisory lists them
- Thomas Wache, Yann Breut, Airbus Defence and Space - Cyber Program: reporting to Siemens
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.