A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.
CVE ID: CVE-2025-40585
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.9
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Vendor: Siemens
Product: Energy Services
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 14.41% (scored less or equal to compared to others)
EPSS Date: 2025-06-17 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: true