CVE-2025-40800: Critical severity COMOS COMOS vulnerability
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40800?
The severity of CVE-2025-40800 is classified as high.
How do I fix CVE-2025-40800?
To fix CVE-2025-40800, update the affected software to the latest versions as specified by Siemens.
Which software versions are affected by CVE-2025-40800?
CVE-2025-40800 affects all versions of Siemens COMOS V10.6, NX V2412 prior to V2412.8700, NX V2506 prior to V2506.6000, Simcenter 3D prior to V2506.6000, Simcenter Femap prior to V2506.0002, and Solid Edge SE2025 prior to V225.0 Update 10.
Is there a workaround for CVE-2025-40800?
There are no known workarounds for CVE-2025-40800; the recommended action is to update the software.
What risks are associated with CVE-2025-40800?
CVE-2025-40800 may lead to unauthorized access and exploitation of the affected software, risking data integrity and confidentiality.