CVE-2025-40752Cleartext Storage of Sensitive Info in Siemens Power Meter Sicam Q100

Severity
6.8MEDIUMNVD
EPSS
0.0%
top 99.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 = V2.60 = V2.60 = V2.60 = V2.70 < V2.80). Affected devices store the password for the SMTP account as plain text. This could allow an authenticated local attacker to extract it and use the configured SMTP service for arbitrary purposes.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5siemens/power_meter_sicam_q100V2.60V2.62
CVEListV5siemens/power_meter_sicam_q200_familyV2.70V2.80

🔴Vulnerability Details

2
GHSA
GHSA-46vw-42gh-2hf4: A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V22025-08-12
CVEList
CVE-2025-40752: A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V22025-08-12
CVE-2025-40752 — Cleartext Storage of Sensitive Info | cvebase