CVE-2025-40567

Description

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.2), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.2), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). The "Load Rollback" functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to make the affected product roll back configuration changes made by privileged users.

Category

7.1
CVSS
Severity: High
CVSS 4.0 •
CVSS 3.1 •
EPSS 0.03%
Affected: Siemens RUGGEDCOM RST2428P
Affected: Siemens SCALANCE XC316-8
Affected: Siemens SCALANCE XC324-4
Affected: Siemens SCALANCE XC324-4 EEC
Affected: Siemens SCALANCE XC332
Affected: Siemens SCALANCE XC416-8
Affected: Siemens SCALANCE XC424-4
Affected: Siemens SCALANCE XC432
Affected: Siemens SCALANCE XCH328
Affected: Siemens SCALANCE XCM324
Affected: Siemens SCALANCE XCM328
Affected: Siemens SCALANCE XCM332
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8 EEC
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC)
Affected: Siemens SCALANCE XRM334 (230 V AC, 12xFO)
Affected: Siemens SCALANCE XRM334 (230 V AC, 8xFO)
Affected: Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)
Affected: Siemens SCALANCE XRM334 (24 V DC, 12xFO)
Affected: Siemens SCALANCE XRM334 (24 V DC, 8xFO)
Affected: Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)
Affected: Siemens SCALANCE XRM334 (2x230 V AC, 12xFO)
Affected: Siemens SCALANCE XRM334 (2x230 V AC, 8xFO)
Affected: Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-40567?
CVE-2025-40567 has been scored as a high severity vulnerability.
How to fix CVE-2025-40567?
To fix CVE-2025-40567, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2025-40567 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-40567 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-40567?
CVE-2025-40567 affects Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XC316-8, Siemens SCALANCE XC324-4, Siemens SCALANCE XC324-4 EEC, Siemens SCALANCE XC332, Siemens SCALANCE XC416-8, Siemens SCALANCE XC424-4, Siemens SCALANCE XC432, Siemens SCALANCE XCH328, Siemens SCALANCE XCM324, Siemens SCALANCE XCM328, Siemens SCALANCE XCM332, Siemens SCALANCE XR302-32, Siemens SCALANCE XR302-32, Siemens SCALANCE XR302-32, Siemens SCALANCE XR322-12, Siemens SCALANCE XR322-12, Siemens SCALANCE XR322-12, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8 EEC, Siemens SCALANCE XR502-32, Siemens SCALANCE XR502-32, Siemens SCALANCE XR502-32, Siemens SCALANCE XR522-12, Siemens SCALANCE XR522-12, Siemens SCALANCE XR522-12, Siemens SCALANCE XR526-8, Siemens SCALANCE XR526-8, Siemens SCALANCE XR526-8, Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC), Siemens SCALANCE XRM334 (230 V AC, 12xFO), Siemens SCALANCE XRM334 (230 V AC, 8xFO), Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), Siemens SCALANCE XRM334 (24 V DC, 12xFO), Siemens SCALANCE XRM334 (24 V DC, 8xFO), Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+), Siemens SCALANCE XRM334 (2x230 V AC, 12xFO), Siemens SCALANCE XRM334 (2x230 V AC, 8xFO), Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.