9.2

CVE-2025-40801

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSiemens
Produkt COMOS V10.6
Default Statusunknown
Version < *
Version 0
Status affected
HerstellerSiemens
Produkt COMOS V10.6
Default Statusunknown
Version < *
Version 0
Status affected
HerstellerSiemens
Produkt JT Bi-Directional Translator for STEP
Default Statusunknown
Version < *
Version 0
Status affected
HerstellerSiemens
Produkt NX V2412
Default Statusunknown
Version < V2412.8900
Version 0
Status affected
HerstellerSiemens
Produkt NX V2506
Default Statusunknown
Version < V2506.6000
Version 0
Status affected
HerstellerSiemens
Produkt Simcenter 3D
Default Statusunknown
Version < V2506.6000
Version 0
Status affected
HerstellerSiemens
Produkt Simcenter Femap
Default Statusunknown
Version < V2506.0002
Version 0
Status affected
HerstellerSiemens
Produkt Simcenter Studio
Default Statusunknown
Version < *
Version 0
Status affected
HerstellerSiemens
Produkt Simcenter System Architect
Default Statusunknown
Version < *
Version 0
Status affected
HerstellerSiemens
Produkt Tecnomatix Plant Simulation
Default Statusunknown
Version < V2504.0007
Version 0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.046
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
productcert@siemens.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
productcert@siemens.com 9.2 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.