CVE-2025-40801
Published: Dec 9, 2025
Modified: Mar 10, 2026
CVSS v3.1
8.1
Description
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
| Vendor | Product | Versions |
|---|---|---|
Siemens | COMOS V10.6 | affected 0 - < V10.6.1 |
Siemens | COMOS V10.6 | affected 0 - < V10.6.1 |
Siemens | JT Bi-Directional Translator for STEP | affected 0 - < * |
Siemens | NX V2412 | affected 0 - < V2412.8900 |
Siemens | NX V2506 | affected 0 - < V2506.6000 |
Siemens | Simcenter 3D | affected 0 - < V2506.6000 |
Siemens | Simcenter Femap | affected 0 - < V2506.0002 |
Siemens | Simcenter Studio | affected 0 - < V2506.0001 |
Siemens | Simcenter System Architect | affected 0 - < V2506.0001 |
Siemens | Tecnomatix Plant Simulation | affected 0 - < V2504.0007 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now