Security Advisory

CVE-2025-40805

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-13 09:44:03
Last updated 2026-05-12 08:20:44
Assigner siemens
CVSS score 10.0
State PUBLISHED

Description

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.