Full Report
SIMATIC Virtualization as a Service (SIVaaS) is affected by a vulnerability which exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization. Siemens recommends to contact technical support to fix the vulnerability.
Analysis Summary
# Vulnerability: Unauthenticated Network Share Exposure in SIMATIC Virtualization as a Service (SIVaaS)
## CVE Details
- CVE ID: CVE-2025-40804
- CVSS Score: 9.1 (CVSS v3.1) | 9.3 (CVSS v4.0) (Critical)
- CWE: CWE-732: Incorrect Permission Assignment for Critical Resource
## Affected Systems
- Products: SIMATIC Virtualization as a Service (SIVaaS)
- Versions: All versions affected. Specific MLFB numbers mentioned: 9LA1110-6SV40-5DA3, 9LA1110-6SV40-5FA3, 9LA1110-6SV40-5FB3, 9LA1110-6SV40-5FC3, 9LA1110-6SV40-5JA2, 9LA1110-6SV40-5XA2, 9LA1110-6SV40-5XA3.
- Configurations: Not specifically defined, as all versions are noted as affected.
## Vulnerability Description
The affected application, SIMATIC Virtualization as a Service (SIVaaS), exposes a network share that is accessible without requiring any authentication. This flaw allows an external attacker to gain unauthorized access to sensitive data hosted on the share, or potentially alter (write/modify) that data.
## Exploitation
- Status: Information does not confirm if it is *in the wild*, but vulnerability details suggest direct exploitability.
- Complexity: Low (CVSS v3.1 Vector: AC:L, PR:N, UI:N)
- Attack Vector: Network (CVSS v3.1 AV:N)
## Impact
- Confidentiality: High (Read sensitive data)
- Integrity: High (Alter sensitive data)
- Availability: Low (CVSS v3.1 A:N - No indication of denial of service impact)
## Remediation
### Patches
- No specific patch version is listed in the advisory.Siemens explicitly recommends contacting technical support to fix the vulnerability.
### Workarounds
- **Contact Technical Support:** Mandated action for remediation.
- **General Security:** Protect network access to devices using appropriate mechanisms.
- **Configuration:** Configure the environment according to Siemens' operational guidelines for Industrial Security.
## Detection
- Detection methods were not explicitly provided, but monitoring network traffic targeting SMB/CIFS protocols for the SIVaaS service attempting connections without valid credentials would be advisable. An indicator of compromise would be unexpected read or write operations on the exposed network share.
## References
- Vendor Advisory: SSA-534283
- General Security Guidelines: hxxps://www.siemens.com/cert/operational-guidelines-industrial-security
- Siemens Industrial Security Hub: hxxps://www.siemens.com/industrialsecurity