CVE Database
/

CVE-2025-40801

Back to search

CVE-2025-40801

Published: Dec 9, 2025

Modified: Mar 10, 2026

PUBLISHED

CVSS v3.1

8.1

HIGH

Description

A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

VendorProductVersions

Siemens

COMOS V10.6

affected
0 - < V10.6.1

Siemens

COMOS V10.6

affected
0 - < V10.6.1

Siemens

JT Bi-Directional Translator for STEP

affected
0 - < *

Siemens

NX V2412

affected
0 - < V2412.8900

Siemens

NX V2506

affected
0 - < V2506.6000

Siemens

Simcenter 3D

affected
0 - < V2506.6000

Siemens

Simcenter Femap

affected
0 - < V2506.0002

Siemens

Simcenter Studio

affected
0 - < V2506.0001

Siemens

Simcenter System Architect

affected
0 - < V2506.0001

Siemens

Tecnomatix Plant Simulation

affected
0 - < V2504.0007

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now