CVE-2025-40819 MEDIUM

CVE-2025-40819

Vendor Siemens
Product SINEMA Remote Connect Server
Weakness CWE-863 · Incorrect authorization
Published December 9, 2025
Last update December 9, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This could allow with database access to circumvent licensing restrictions by directly modifying database values and potentially enabling unauthorized use beyond the permitted scope.

Key dates

02Disclosure timeline

December 9, 2025 CVE published
December 9, 2025 Record updated