CVE-2025-40767

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate security controls to enforce isolation. This could allow an attacker to gain elevated access, potentially accessing sensitive host system resources.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*

History

15 Aug 2025, 18:22

Type Values Removed Values Added
First Time Siemens
Siemens sinec Traffic Analyzer
CPE cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (todas las versiones anteriores a la V3.0). La aplicación afectada ejecuta contenedores Docker sin los controles de seguridad adecuados para aplicar el aislamiento. Esto podría permitir que un atacante obtenga acceso con privilegios elevados, lo que podría afectar a recursos confidenciales del sistema host.
References () https://cert-portal.siemens.com/productcert/html/ssa-517338.html - () https://cert-portal.siemens.com/productcert/html/ssa-517338.html - Vendor Advisory

12 Aug 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 12:15

Updated : 2025-08-15 18:22


NVD link : CVE-2025-40767

Mitre link : CVE-2025-40767

CVE.ORG link : CVE-2025-40767


JSON object : View

Products Affected

siemens

  • sinec_traffic_analyzer
CWE
CWE-250

Execution with Unnecessary Privileges