CVE-2025-40585
CRITICALEnergy Services - All versions with G5DFR - Privilege Escalation
Title source: llmDescription
A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.
Scores
CVSS v3
9.9
EPSS
0.0028
EPSS Percentile
51.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-276
Status
published
Products (1)
Siemens/Energy Services
Published
Jun 10, 2025
Tracked Since
Feb 18, 2026