A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-981622.html | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-14 09:16
Updated : 2026-06-29 14:03
NVD link : CVE-2025-40745
Mitre link : CVE-2025-40745
CVE.ORG link : CVE-2025-40745
JSON object : View
Products Affected
siemens
- solid_edge_se2025
- simcenter_femap
- software_center
- simcenter_3d
- solid_edge_se2026
- simcenter_star-ccm\+_viewer
- tecnomatix_plant_simulation
CWE
CWE-295
Improper Certificate Validation
