CVE-2025-25266: High severity Siemens Tecnomatix Plant Simulation V2302 vulnerability
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict access to the file deletion functionality. This could allow an unauthorized attacker to delete files even when access to the system should be prohibited, resulting in potential data loss or unauthorized modification of system files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tecnomatix Plant Simulationto a version that resolves this vulnerability.Fixed in V2302.0021 - Upgrade
Upgrade
Tecnomatix Plant Simulationto a version that resolves this vulnerability.Fixed in V2404.0010
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25266?
The severity of CVE-2025-25266 is high due to the potential for unauthorized access and file deletion.
How do I fix CVE-2025-25266?
To fix CVE-2025-25266, upgrade Tecnomatix Plant Simulation to version V2302.0021 or V2404.0010 or later.
Which versions of Tecnomatix Plant Simulation are affected by CVE-2025-25266?
Tecnomatix Plant Simulation V2302 (all versions below V2302.0021) and V2404 (all versions below V2404.0010) are affected.
What impact does CVE-2025-25266 have on system security?
CVE-2025-25266 can lead to unauthorized file deletion, compromising the integrity and confidentiality of the system.
Is there a workaround for CVE-2025-25266?
Currently, there are no documented workarounds for CVE-2025-25266; upgrading to the fixed versions is recommended.