CVE-2025-40567 Details
Description
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). The "Load Rollback" functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to make the affected product roll back configuration changes made by privileged users.
An incorrect authorization check vulnerability has been identified in the web interface of several Siemens industrial communication devices running SINEC OS, all versions prior to V3.2. This vulnerability allows an authenticated remote attacker with a 'guest' role to roll back configuration changes made by privileged users. Affected products include RUGGEDCOM RST2428P, various SCALANCE XC and XR families, and specific models within the SCALANCE XCM, XRM, XCH, and XRH series.
Siemens has released version 3.2 for all affected products. Instructions for updating can be found on the Siemens Industry Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-693776.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens RUGGEDCOM RST2428P | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC316-8 | All versions |
CPE
Remediation
| |
| Siemens SCALANCE XC324-4 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC324-4 EEC | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC332 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC416-8 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC424-4 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XC432 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XCH328 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XCM324 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XCM328 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XCM332 | All versions |
CPE
Remediation
| |
| Siemens SCALANCE XR302-32 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR322-12 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR326-8 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR326-8 EEC | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR502-32 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR522-12 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XR526-8 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XRH334 | < V3.2 |
CPE
Remediation
| |
| Siemens SCALANCE XRM334 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2026 | CVE Modified | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |
Volerion