{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Disclosure is not limited. (TLPv2: TLP:CLEAR)",
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Heliox EV Chargers listed below contain improper access control vulnerability that could allow an attacker to reach unauthorized services via the charging cable.\n\nSiemens has released new versions for the affected products and recommends to update to the latest versions.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity",
        "title": "General Recommendations"
      },
      {
        "category": "general",
        "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories",
        "title": "Additional Resources"
      },
      {
        "category": "legal_disclaimer",
        "text": "The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "productcert@siemens.com",
      "name": "Siemens ProductCERT",
      "namespace": "https://www.siemens.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "SSA-126399: Improper Access Control Vulnerability in Heliox EV Chargers - HTML Version",
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-126399.html"
      },
      {
        "category": "self",
        "summary": "SSA-126399: Improper Access Control Vulnerability in Heliox EV Chargers - CSAF Version",
        "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-126399.json"
      }
    ],
    "title": "SSA-126399: Improper Access Control Vulnerability in Heliox EV Chargers",
    "tracking": {
      "current_release_date": "2026-03-10T00:00:00.000Z",
      "generator": {
        "engine": {
          "name": "Siemens ProductCERT CSAF Generator",
          "version": "1"
        }
      },
      "id": "SSA-126399",
      "initial_release_date": "2026-03-10T00:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-03-10T00:00:00.000Z",
          "legacy_version": "1.0",
          "number": "1",
          "summary": "Publication Date"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "All versions < F4.11.1",
                "product": {
                  "name": "Heliox Flex 180 kW EV Charging Station",
                  "product_id": "1"
                }
              }
            ],
            "category": "product_name",
            "name": "Heliox Flex 180 kW EV Charging Station"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "All versions < L4.10.1",
                "product": {
                  "name": "Heliox Mobile DC 40 kW EV Charging Station",
                  "product_id": "2"
                }
              }
            ],
            "category": "product_name",
            "name": "Heliox Mobile DC 40 kW EV Charging Station"
          }
        ],
        "category": "vendor",
        "name": "Siemens"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-27769",
      "cwe": {
        "id": "CWE-923",
        "name": "Improper Restriction of Communication Channel to Intended Endpoints"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "1",
          "2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Contact customer support for patch information via OTA update",
          "product_ids": [
            "1",
            "2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.6,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "1",
            "2"
          ]
        }
      ],
      "title": "CVE-2025-27769"
    }
  ]
}