CVE-2025-40745: Medium severity Siemens Siemens Software Center vulnerability
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Siemens Software Centerto a version that resolves this vulnerability.Fixed in V3.5.8.2 - Upgrade
Upgrade
Simcenter 3Dto a version that resolves this vulnerability.Fixed in V2506.6000 - Upgrade
Upgrade
Simcenter Femapto a version that resolves this vulnerability.Fixed in V2506.0002 - Upgrade
Upgrade
Simcenter STAR-CCM+to a version that resolves this vulnerability.Fixed in V2602 - Upgrade
Upgrade
Solid Edge SE2025to a version that resolves this vulnerability.Fixed in V225.0 Update 13 - Upgrade
Upgrade
Solid Edge SE2026to a version that resolves this vulnerability.Fixed in V226.0 Update 04 - Upgrade
Upgrade
Tecnomatix Plant Simulationto a version that resolves this vulnerability.Fixed in V2504.0008
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40745?
The severity of CVE-2025-40745 is considered critical due to its impact on multiple Siemens software products.
How do I fix CVE-2025-40745?
To fix CVE-2025-40745, users should upgrade to the latest versions of the affected Siemens software products as specified in the vendor advisories.
What products are affected by CVE-2025-40745?
CVE-2025-40745 affects Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, and Tecnomatix Plant Simulation.
Is my version of Siemens Software Center vulnerable to CVE-2025-40745?
Yes, all versions of Siemens Software Center prior to 3.5.8.2 are vulnerable to CVE-2025-40745.
What should I do if I cannot update my Siemens software to fix CVE-2025-40745?
If you cannot update your Siemens software, you should implement security mitigations to reduce exposure until a patch can be applied.