CVE-2025-40556 Details
Description
A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BACnet ATEC 550-446 (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the targeted device. A power cycle is required to restore the device's normal operation.
A denial-of-service vulnerability has been identified in Siemens BACnet ATEC devices 550-440, 550-441, 550-445, and 550-446, all versions. The vulnerability arises from the devices' improper handling of certain incoming BACnet MSTP messages. This flaw allows an attacker on the same BACnet network to send a specially crafted MSTP message that disrupts the normal operation of the targeted device, creating a denial-of-service condition. To restore functionality, a power cycle is required.
Currently, no fix is planned for this vulnerability. As a general security measure, it is recommended to protect network access to affected products with appropriate mechanisms and to follow recommended security practices to maintain a protected IT environment.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2025CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-828116.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens BACnet ATEC 550-440 | All versions |
CPE
Remediation
| |
| Siemens BACnet ATEC 550-441 | All versions |
CPE
Remediation
| |
| Siemens BACnet ATEC 550-445 | All versions |
CPE
Remediation
| |
| Siemens BACnet ATEC 550-446 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |
Volerion