Home

Description

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-09 | Updated 2025-12-09 | Assigner siemens




HIGH: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CRITICAL: 9.1CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-295: Improper Certificate Validation

Product status

Default status
unknown

Any version before *
affected

Default status
unknown

Any version before *
affected

Default status
unknown

Any version before V2412.8700
affected

Default status
unknown

Any version before V2506.6000
affected

Default status
unknown

Any version before V2506.6000
affected

Default status
unknown

Any version before V2506.0002
affected

Default status
unknown

Any version before V225.0 Update 10
affected

Default status
unknown

Any version before V226.0 Update 1
affected

References

cert-portal.siemens.com/productcert/html/ssa-868571.html

cert-portal.siemens.com/productcert/html/ssa-212953.html

cve.org (CVE-2025-40800)

nvd.nist.gov (CVE-2025-40800)

Download JSON