CVE-2025-40897

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administrative actions on it, altering the rules configuration, and/or affecting their availability.
Configurations

No configuration.

History

12 May 2026, 13:17

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-827968.html -

15 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-15 09:16

Updated : 2026-05-12 13:17


NVD link : CVE-2025-40897

Mitre link : CVE-2025-40897

CVE.ORG link : CVE-2025-40897


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization