SSO Login Service Vulnerability in Teamcenter by Siemens
CVE-2025-23363

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 February 2025

Badges

📰 News Worthy

Summary

A vulnerability in the SSO login service of Teamcenter affects all versions prior to V14.3.0.0. This flaw allows attackers to manipulate user-controlled input, potentially redirecting users to malicious external sites. If a user clicks on a crafted link provided by an attacker, their session data could be compromised, leading to unauthorized access and potential data breaches.

Affected Version(s)

Teamcenter V14.1 0

Teamcenter V14.2 0

Teamcenter V14.3 0

News Articles

Siemens Teamcenter vulnerability could allow account takeover (CVE-2025-23363) - Help Net Security

A vulnerability (CVE-2025-23363) in the Siemens Teamcenter PLM software could allow an attacker to steal users' valid session data.

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 📰

    First article discovered by Help Net Security

  • Vulnerability published

  • Vulnerability Reserved

.