PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40736 Siemens CVE debrief

CVE-2025-40736 is a critical vulnerability in Siemens SINEC NMS where an exposed endpoint can be used to modify administrative credentials without authorization. According to the advisory, an unauthenticated attacker could reset the superadmin password and gain full control of the application. Siemens advises updating to V4.0 or later.

Vendor
Siemens
Product
SINEC NMS
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-08
Original CVE updated
2025-07-08
Advisory published
2025-07-08
Advisory updated
2025-07-08

Who should care

Organizations running Siemens SINEC NMS, especially OT/industrial operations teams, platform administrators, and security teams responsible for externally reachable management interfaces or privileged account protection.

Technical summary

The advisory describes a network-reachable issue with no authentication required (CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The affected application exposes an endpoint that permits unauthorized modification of administrative credentials, enabling password reset of the superadmin account and resulting in full administrative compromise if abused.

Defensive priority

Immediate / urgent. This is a critical, remotely reachable, unauthenticated administrative takeover issue with high confidentiality, integrity, and availability impact.

Recommended defensive actions

  • Update Siemens SINEC NMS to V4.0 or later as directed by Siemens.
  • Restrict network exposure of SINEC NMS management interfaces to trusted administrative networks only.
  • Review privileged account activity for unexpected password changes, logins, or configuration changes.
  • If compromise is suspected, rotate administrative credentials and assess for unauthorized changes across the application and connected systems.
  • Follow CISA and Siemens industrial control system hardening guidance for defense-in-depth and access control.

Evidence notes

The supplied CISA CSAF advisory for ICSA-25-191-01 states that the affected application exposes an endpoint allowing unauthorized modification of administrative credentials and that this could let an unauthenticated attacker reset the superadmin password and gain full control of the application. The provided CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) supports remote, no-auth, high-impact risk. The only remediation explicitly provided in the source corpus is to update to V4.0 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40736 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40736

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40736 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40736

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-191-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-078892.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-078892.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.