CVE-2025-40569

Description

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.2), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.2), SCALANCE XC332 (6GK5332-0GA00-2AC2) (All versions < V3.2), SCALANCE XC416-8 (6GK5424-8TR00-2AC2) (All versions < V3.2), SCALANCE XC424-4 (6GK5428-4TR00-2AC2) (All versions < V3.2), SCALANCE XC432 (6GK5432-0GR00-2AC2) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-2AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-3AR3) (All versions < V3.2), SCALANCE XR302-32 (6GK5334-5TS00-4AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-2AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-3AR3) (All versions < V3.2), SCALANCE XR322-12 (6GK5334-3TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-2AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-3AR3) (All versions < V3.2), SCALANCE XR326-8 (6GK5334-2TS00-4AR3) (All versions < V3.2), SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-2AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-3AR3) (All versions < V3.2), SCALANCE XR502-32 (6GK5534-5TR00-4AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-2AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-3AR3) (All versions < V3.2), SCALANCE XR522-12 (6GK5534-3TR00-4AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-2AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-3AR3) (All versions < V3.2), SCALANCE XR526-8 (6GK5534-2TR00-4AR3) (All versions < V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions < V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions < V3.2). The "Load Configuration from Local PC" functionality in the web interface of affected products contains a race condition vulnerability. This could allow an authenticated remote attacker to make the affected product load an attacker controlled configuration instead of the legitimate one. Successful exploitation requires that a legitimate administrator invokes the functionality and the attacker wins the race condition.

Category

5.9
CVSS
Severity: Medium
CVSS 4.0 •
CVSS 3.1 •
EPSS 0.03%
Affected: Siemens RUGGEDCOM RST2428P
Affected: Siemens SCALANCE XC316-8
Affected: Siemens SCALANCE XC324-4
Affected: Siemens SCALANCE XC324-4 EEC
Affected: Siemens SCALANCE XC332
Affected: Siemens SCALANCE XC416-8
Affected: Siemens SCALANCE XC424-4
Affected: Siemens SCALANCE XC432
Affected: Siemens SCALANCE XCH328
Affected: Siemens SCALANCE XCM324
Affected: Siemens SCALANCE XCM328
Affected: Siemens SCALANCE XCM332
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR302-32
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR322-12
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8
Affected: Siemens SCALANCE XR326-8 EEC
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR502-32
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR522-12
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XR526-8
Affected: Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC)
Affected: Siemens SCALANCE XRM334 (230 V AC, 12xFO)
Affected: Siemens SCALANCE XRM334 (230 V AC, 8xFO)
Affected: Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)
Affected: Siemens SCALANCE XRM334 (24 V DC, 12xFO)
Affected: Siemens SCALANCE XRM334 (24 V DC, 8xFO)
Affected: Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)
Affected: Siemens SCALANCE XRM334 (2x230 V AC, 12xFO)
Affected: Siemens SCALANCE XRM334 (2x230 V AC, 8xFO)
Affected: Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-40569?
CVE-2025-40569 has been scored as a medium severity vulnerability.
How to fix CVE-2025-40569?
To fix CVE-2025-40569, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2025-40569 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-40569 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-40569?
CVE-2025-40569 affects Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XC316-8, Siemens SCALANCE XC324-4, Siemens SCALANCE XC324-4 EEC, Siemens SCALANCE XC332, Siemens SCALANCE XC416-8, Siemens SCALANCE XC424-4, Siemens SCALANCE XC432, Siemens SCALANCE XCH328, Siemens SCALANCE XCM324, Siemens SCALANCE XCM328, Siemens SCALANCE XCM332, Siemens SCALANCE XR302-32, Siemens SCALANCE XR302-32, Siemens SCALANCE XR302-32, Siemens SCALANCE XR322-12, Siemens SCALANCE XR322-12, Siemens SCALANCE XR322-12, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8, Siemens SCALANCE XR326-8 EEC, Siemens SCALANCE XR502-32, Siemens SCALANCE XR502-32, Siemens SCALANCE XR502-32, Siemens SCALANCE XR522-12, Siemens SCALANCE XR522-12, Siemens SCALANCE XR522-12, Siemens SCALANCE XR526-8, Siemens SCALANCE XR526-8, Siemens SCALANCE XR526-8, Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC), Siemens SCALANCE XRM334 (230 V AC, 12xFO), Siemens SCALANCE XRM334 (230 V AC, 8xFO), Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), Siemens SCALANCE XRM334 (24 V DC, 12xFO), Siemens SCALANCE XRM334 (24 V DC, 8xFO), Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+), Siemens SCALANCE XRM334 (2x230 V AC, 12xFO), Siemens SCALANCE XRM334 (2x230 V AC, 8xFO), Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.