CVE-2025-40800
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2025-40800 is an improper certificate validation vulnerability affecting the IAM (Identity and Access Management) client in multiple Siemens industrial and engineering software products. The flaw causes the IAM client to skip server certificate validation when establishing TLS connections to the authorization server, enabling man-in-the-middle (MitM) attacks. Affected products include COMOS V10.6 (all versions < V10.6.1), NX V2412 (< V2412.8700), NX V2506 (< V2506.6000), Simcenter 3D (< V2506.6000), Simcenter Femap (< V2506.0002), Solid Edge SE2025 (< V225.0 Update 10), and Solid Edge SE2026 (< V226.0 Update 1). The vulnerability was published on December 9, 2025, with a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 9.1 (Critical) (Siemens CERT, CISA ICS Advisory).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation). The IAM client component in the affected Siemens products fails to validate the server's TLS certificate when connecting to the authorization server, meaning it does not verify that the server it is communicating with is legitimate. An attacker positioned on the network path between the client and the authorization server (e.g., via ARP spoofing or DNS poisoning) can present a rogue certificate and intercept or modify the TLS-protected communication. No user interaction is required, and no privileges are needed to exploit this flaw, though the attack complexity is rated High due to the requirement for a network-adjacent or on-path position. This vulnerability maps to CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (Siemens CERT, CISA ICS Advisory).

Impact

Successful exploitation allows an attacker to intercept and potentially modify TLS-encrypted communications between the IAM client and the authorization server, resulting in high confidentiality and integrity impact with no availability impact. Sensitive data such as authentication credentials, session tokens, and authorization responses could be captured or tampered with, potentially enabling unauthorized access to affected Siemens engineering environments. Given that the affected products are used in industrial design, plant engineering, and simulation contexts, credential compromise could facilitate further lateral movement into sensitive operational technology (OT) or engineering networks (Siemens CERT, CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify target environments running affected Siemens products (COMOS, NX, Simcenter 3D, Simcenter Femap, Solid Edge) that use the IAM client for authentication against an authorization server.
  2. Network Positioning: Gain a man-in-the-middle position on the network segment between the client workstation and the authorization server using techniques such as ARP spoofing, DNS poisoning, or rogue Wi-Fi access point deployment.
  3. TLS Interception Setup: Deploy a TLS interception proxy (e.g., mitmproxy, Burp Suite) configured with a self-signed or attacker-controlled certificate for the authorization server's hostname.
  4. Intercept IAM Client Traffic: When the affected IAM client initiates a TLS connection to the authorization server, the proxy presents the rogue certificate. Because the client does not validate the server certificate, the TLS handshake completes successfully.
  5. Credential/Token Capture or Manipulation: Capture plaintext authentication credentials, OAuth tokens, or session data transmitted by the IAM client. Optionally, modify authorization responses to escalate privileges or inject malicious data before forwarding to the legitimate server.
  6. Leverage Captured Credentials: Use the intercepted credentials or tokens to authenticate to the Siemens product environment or connected systems, enabling unauthorized access or further lateral movement (Siemens CERT, CISA ICS Advisory).

Indicators of compromise

  • Network: Unexpected TLS connections from client workstations to IP addresses not matching the legitimate authorization server; TLS certificates presented to IAM clients with unexpected issuers or subject names; ARP table anomalies indicating ARP spoofing on the network segment hosting affected Siemens products.
  • Logs: Authentication events from unexpected source IPs or at unusual times in authorization server logs; failed or anomalous TLS handshake entries in network monitoring tools; duplicate MAC address entries in switch logs suggesting ARP poisoning.
  • Process/Behavior: Unusual network traffic patterns from workstations running COMOS, NX, Simcenter, or Solid Edge to non-standard IP addresses during IAM authentication flows.

Mitigation and workarounds

Siemens has released patched versions for most affected products: NX V2412 (update to V2412.8700 or later), NX V2506 (update to V2506.6000 or later), Simcenter 3D (update to V2506.6000 or later), Simcenter Femap (update to V2506.0002 or later), Solid Edge SE2025 (update to V225.0 Update 10 or later), and Solid Edge SE2026 (update to V226.0 Update 1 or later). For COMOS V10.6, no patch was available at initial disclosure — users should consult Siemens for the latest guidance. As a general workaround, organizations should restrict network access to authorization servers, implement network segmentation to prevent unauthorized MitM positioning, and monitor for ARP spoofing or DNS manipulation on affected network segments (Siemens CERT, CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-25-345-04) on December 11, 2025, highlighting the vulnerability and recommending users apply Siemens patches and follow ICS security best practices (CISA ICS Advisory). A follow-up CISA advisory (ICSA-26-043-03) was published in February 2026, indicating continued tracking of the issue. Security news outlets including IT Security News and BeyondMachines covered the disclosure, noting that Siemens COMOS was affected by multiple flaws including at least one rated critical (BeyondMachines). Community reaction on social platforms was limited, consistent with the low EPSS score and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management