PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40807 Siemens CVE debrief

A capture-replay vulnerability in Siemens Gridscale X Prepay allows an authenticated but locked-out user to re-establish valid sessions by replaying previously captured authentication tokens. The flaw stems from insufficient token invalidation upon account lockout, enabling session resurrection without fresh authentication. With a CVSS 6.3 (Medium), this poses moderate risk in operational technology environments where prepayment systems manage critical utility infrastructure. The attack requires network access and prior valid credentials, but no user interaction. Organizations should contact Siemens representatives for remediation guidance and implement network segmentation to limit token exposure.

Vendor
Siemens
Product
Gridscale X Prepay
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-09
Original CVE updated
2026-10-07
Advisory published
2025-12-09
Advisory updated
2026-10-07

Who should care

Organizations operating Siemens Gridscale X Prepay systems for utility prepayment management, particularly in critical infrastructure sectors. Security teams responsible for OT/ICS authentication and session management controls. Compliance officers tracking CVE remediation for industrial control system environments.

Technical summary

The Gridscale X Prepay application fails to properly invalidate authentication tokens when a user account is locked out. An attacker with prior network access can capture valid tokens and replay them to establish new sessions even after the legitimate user has been administratively locked out. The vulnerability is network-exploitable with low attack complexity, requiring low privileges but no user interaction. Impact is limited to confidentiality, integrity, and availability (low severity each) due to the authenticated nature of the attack.

Defensive priority

medium

Recommended defensive actions

  • Contact your local Siemens representative to obtain vendor fix information for Gridscale X Prepay
  • Implement network segmentation to limit exposure of authentication tokens in transit
  • Review and strengthen session management controls to ensure tokens are invalidated upon account lockout
  • Monitor for anomalous session establishment patterns from previously locked-out accounts
  • Apply CISA ICS recommended practices for defense-in-depth in industrial control environments

Evidence notes

CISA ICS advisory ICSA-25-345-09 confirms the vulnerability description and vendor attribution. Siemens product security advisory SSA-356310 provides authoritative vendor remediation guidance. CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L sourced from CISA CSAF data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40807 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40807

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40807 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40807

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-356310.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-356310.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.