Status: UPDATED
| Advisory ID: CVE-2025-40899
Key Details
| CVE | CVE-2025-40899 |
| CVSS Score / Version | 8.9 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is high. |
| Affected products | Nozomi Networks Guardian, Nozomi Networks CMC, and Siemens RUGGEDCOM APE1808 |
| Classified as | CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information. (NVD)
What to Do
Monitor Nozomi Networks's and Siemens's web pages for any future patch releases.
References