CVE-2025-40801: Critical severity Siemens COMOS vulnerability
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40801?
The severity of CVE-2025-40801 has been classified as critical due to its potential for remote code execution.
How do I fix CVE-2025-40801?
To remediate CVE-2025-40801, users should update affected products to their latest versions as specified by Siemens.
What products are affected by CVE-2025-40801?
CVE-2025-40801 affects COMOS V10.6, Siemens NX V2412 (versions below V2412.8900), NX V2506 (versions below V2506.6000), among others.
Is there a workaround for CVE-2025-40801?
A temporary workaround for CVE-2025-40801 may involve applying specific configuration changes, but full remediation is achieved through version updates.
When was CVE-2025-40801 disclosed?
CVE-2025-40801 was disclosed in 2025 as part of Siemens’ ongoing security monitoring efforts.