CVE-2025-25267: Medium severity Siemens Tecnomatix Plant Simulation V2302 vulnerability
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict the scope of files accessible to the simulation model. This could allow an unauthorized attacker to compromise the confidentiality of the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tecnomatix Plant Simulationto a version that resolves this vulnerability.Fixed in V2302.0021 - Upgrade
Upgrade
Tecnomatix Plant Simulationto a version that resolves this vulnerability.Fixed in V2404.0010
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25267?
CVE-2025-25267 is classified as a medium severity vulnerability due to improper file access restrictions.
How do I fix CVE-2025-25267?
To fix CVE-2025-25267, users should update to Tecnomatix Plant Simulation V2302.0021 or V2404.0010 or later.
What are the affected versions of Tecnomatix Plant Simulation for CVE-2025-25267?
CVE-2025-25267 affects Tecnomatix Plant Simulation V2302 versions below V2302.0021 and V2404 versions below V2404.0010.
What type of attacks can CVE-2025-25267 facilitate?
CVE-2025-25267 can potentially allow unauthorized access to sensitive files within the simulation model.
Who is responsible for addressing CVE-2025-25267?
The vendor, Siemens, is responsible for addressing CVE-2025-25267 through software updates and patches.