Man-in-the-Middle Attack Vulnerability in Siemens Solid Edge SE2025
CVE-2025-40744

8.7HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
11 November 2025

What is CVE-2025-40744?

A vulnerability exists in Solid Edge SE2025 where client certificates are not properly validated for connections to the License Service endpoint. This oversight can be exploited by an unauthenticated remote attacker, potentially leading to man-in-the-middle attacks that could jeopardize sensitive data and communications.

Affected Version(s)

Solid Edge SE2025 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40744 : Man-in-the-Middle Attack Vulnerability in Siemens Solid Edge SE2025