216.73.217.22

CVE-2025-40745

· Published 14/04/2026 09:16 · Modified 14/04/2026 09:16

Labels: CVE-2025-40745 2026-04-14CVE-2025-40745CWE-295[email protected]

Essential information

Published
14/04/2026 09:16
Modified
14/04/2026 09:16
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
siemens / siemens software center cpe:2.3:a:siemens:siemens_software_center:<3.5.8.2:*:*:*:*:*:*:*
siemens / simcenter 3d cpe:2.3:a:siemens:simcenter_3d:<V2506.6000:*:*:*:*:*:*:*
siemens / simcenter femap cpe:2.3:a:siemens:simcenter_femap:<V2506.0002:*:*:*:*:*:*:*
siemens / simcenter star-ccm+ cpe:2.3:a:siemens:simcenter_star-ccm+:<V2602:*:*:*:*:*:*:*
siemens / solid edge se2025 cpe:2.3:a:siemens:solid_edge_se2025:<V225.0_update_13:*:*:*:*:*:*:*
siemens / solid edge se2026 cpe:2.3:a:siemens:solid_edge_se2026:<V226.0_update_04:*:*:*:*:*:*:*
siemens / tecnomatix plant simulation cpe:2.3:a:siemens:tecnomatix_plant_simulation:<V2504.0008:*:*:*:*:*:*:*

References