Man-in-the-Middle Attack Vulnerability in Siemens Software
CVE-2025-40745

6.3MEDIUM

What is CVE-2025-40745?

A security vulnerability exists within various Siemens software products that fail to adequately validate client certificates during connections to the Analytics Service endpoint. This flaw exposes the applications to man-in-the-middle attacks, where an unauthenticated remote attacker could potentially intercept and manipulate communications, compromising the confidentiality and integrity of data transmitted between the client and the server.

Affected Version(s)

Siemens Software Center 0

Simcenter 3D 0

Simcenter Femap 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.