← All Advisories

CVE-2025-40899

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-40899

Key Details

CVECVE-2025-40899
CVSS Score / Version8.9 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is high.
Affected productsNozomi Networks Guardian, Nozomi Networks CMC, and Siemens RUGGEDCOM APE1808
Classified asCWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Nozomi NetworksGuardian
Nozomi NetworksCMC
SiemensRUGGEDCOM APE1808
SubsystemsGeneral OT
SectorsMultiple

What to Know

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information. (NVD)

What to Do

Monitor Nozomi Networks's and Siemens's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-40899
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-40899