CVE-2025-40805
10.0Siemens · Industrial Edge Cloud Device (IECD)
Siemens Industrial Edge Cloud Device (IECD) and Edge Device Kit are vulnerable to an authentication bypass via specific API endpoints, allowing unauthenticated remote attackers to impersonate users.
Executive summary
A critical authentication bypass vulnerability in Siemens Industrial Edge devices allows unauthenticated remote attackers to impersonate legitimate users and achieve full system compromise.
Vulnerability
The vulnerability exists due to improper enforcement of user authentication on specific API endpoints (CWE-639). This allows an unauthenticated remote attacker to bypass security controls, provided they have identified a valid user's identity.
Business impact
The exploitation of this vulnerability results in a total loss of confidentiality, integrity, and availability, justifying the maximum CVSS score of 10.0. An attacker gaining administrative-level access to industrial edge controllers could disrupt manufacturing processes, exfiltrate sensitive operational data, or pivot into deeper segments of the industrial control network, leading to significant operational downtime and potential safety risks.
Remediation
Immediate Action: Update Siemens Industrial Edge Cloud Device (IECD) to version V1.24.2 or later; for Edge Device Kit users, consult the vendor security portal for specific mitigation or update paths.
Proactive Monitoring: Monitor API access logs for unusual patterns, such as multiple failed or suspicious authentication requests or successful logins originating from non-standard IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) or industrial-grade network firewall to restrict access to API endpoints to known, authorized management IP addresses only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for full system compromise, organizations should prioritize patching affected Siemens IECD units immediately. If immediate patching is not feasible, restrict network access to the affected API endpoints as a primary defensive measure to prevent unauthorized access.