CNNVD-202509-1427 Information

CNNVD ID

CNNVD-202509-1427

CVE-2025-40594

  • CNNVD Published: 2025-09-09

Description (Chinese)

Siemens SINAMICS S200等都是德国西门子(Siemens)公司的产品。Siemens SINAMICS S200是一款单轴交流伺服驱动系统。Siemens SINAMICS G220是一款可变频驱动器。Siemens SINAMICS S210是一款可变频驱动器。 Siemens多款产品存在安全漏洞,该漏洞源于权限管理不当,可能导致权限提升。以下产品和版本受到影响:SINAMICS G220 V6.4版本、SINAMICS S200 V6.4版本和SINAMICS S210 V6.4版本。

Description (English)

Siemens SINAMIS S200 and others are products of Siemens Germany. Siemens SINAMICSS200 is a single-axis communication server driver. Siemens SINAMICS G220 is a variable frequency drive. Siemens SINAMIS S210 is a variable frequency drive. There is a safety gap in multiple Siemens products, which stems from inadequate authority management, which could lead to increased authority. The following products and versions were affected: SINAMICS G220 V6.4, SINAMICS S200 V6.4 and SINAMICS S210 V6.4.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

西门子

Published

2025-09-09

Last Modified

2026-02-24

References

https://cert-portal.siemens.com/productcert/html/ssa-027652.html

Patch

https://support.industry.siemens.com/cs/document/109983183/sinamics-g220-firmware-v6-4-hf2?dti=0&lc=en-WW

Share on: