PatchSiren cyber security CVE debrief
CVE-2025-40807 Siemens CVE debrief
A capture-replay vulnerability in Siemens Gridscale X Prepay allows an authenticated but locked-out user to re-establish valid sessions by replaying previously captured authentication tokens. The flaw stems from insufficient token invalidation upon account lockout, enabling session resurrection without fresh authentication. With a CVSS 6.3 (Medium), this poses moderate risk in operational technology environments where prepayment systems manage critical utility infrastructure. The attack requires network access and prior valid credentials, but no user interaction. Organizations should contact Siemens representatives for remediation guidance and implement network segmentation to limit token exposure.
- Vendor
- Siemens
- Product
- Gridscale X Prepay
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-09
- Original CVE updated
- 2026-10-07
- Advisory published
- 2025-12-09
- Advisory updated
- 2026-10-07
Who should care
Organizations operating Siemens Gridscale X Prepay systems for utility prepayment management, particularly in critical infrastructure sectors. Security teams responsible for OT/ICS authentication and session management controls. Compliance officers tracking CVE remediation for industrial control system environments.
Technical summary
The Gridscale X Prepay application fails to properly invalidate authentication tokens when a user account is locked out. An attacker with prior network access can capture valid tokens and replay them to establish new sessions even after the legitimate user has been administratively locked out. The vulnerability is network-exploitable with low attack complexity, requiring low privileges but no user interaction. Impact is limited to confidentiality, integrity, and availability (low severity each) due to the authenticated nature of the attack.
Defensive priority
medium
Recommended defensive actions
- Contact your local Siemens representative to obtain vendor fix information for Gridscale X Prepay
- Implement network segmentation to limit exposure of authentication tokens in transit
- Review and strengthen session management controls to ensure tokens are invalidated upon account lockout
- Monitor for anomalous session establishment patterns from previously locked-out accounts
- Apply CISA ICS recommended practices for defense-in-depth in industrial control environments
Evidence notes
CISA ICS advisory ICSA-25-345-09 confirms the vulnerability description and vendor attribution. Siemens product security advisory SSA-356310 provides authoritative vendor remediation guidance. CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L sourced from CISA CSAF data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40807 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40807
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40807 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40807
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-356310.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-356310.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.