A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.

Project Subscriptions

Vendors Products
Siemens Subscribe
Simcenter 3d Subscribe
Simcenter Femap Subscribe
Simcenter Star-ccm\+ Subscribe
Software Center Subscribe
Solid Edge Se2025 Subscribe
Solid Edge Se2026 Subscribe
Tecnomatix Plant Simulation Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Title Improper Client‑Certificate Validation Enables Man‑in‑the‑Middle Attacks in Siemens Software Products

Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simcenter 3d
Siemens simcenter Femap
Siemens simcenter Star-ccm\+
Siemens software Center
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Siemens tecnomatix Plant Simulation
Vendors & Products Siemens
Siemens simcenter 3d
Siemens simcenter Femap
Siemens simcenter Star-ccm\+
Siemens software Center
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Siemens tecnomatix Plant Simulation

Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-04-14T13:38:29.751Z

Reserved: 2025-04-16T08:39:30.030Z

Link: CVE-2025-40745

cve-icon Vulnrichment

Updated: 2026-04-14T13:38:03.182Z

cve-icon NVD

Status : Received

Published: 2026-04-14T09:16:34.683

Modified: 2026-04-14T09:16:34.683

Link: CVE-2025-40745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:30:41Z

Weaknesses