
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40800 is an improper certificate validation vulnerability affecting the IAM (Identity and Access Management) client in multiple Siemens industrial and engineering software products. The flaw causes the IAM client to skip server certificate validation when establishing TLS connections to the authorization server, enabling man-in-the-middle (MitM) attacks. Affected products include COMOS V10.6 (all versions < V10.6.1), NX V2412 (< V2412.8700), NX V2506 (< V2506.6000), Simcenter 3D (< V2506.6000), Simcenter Femap (< V2506.0002), Solid Edge SE2025 (< V225.0 Update 10), and Solid Edge SE2026 (< V226.0 Update 1). The vulnerability was published on December 9, 2025, with a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 9.1 (Critical) (Siemens CERT, CISA ICS Advisory).
The root cause is classified as CWE-295 (Improper Certificate Validation). The IAM client component in the affected Siemens products fails to validate the server's TLS certificate when connecting to the authorization server, meaning it does not verify that the server it is communicating with is legitimate. An attacker positioned on the network path between the client and the authorization server (e.g., via ARP spoofing or DNS poisoning) can present a rogue certificate and intercept or modify the TLS-protected communication. No user interaction is required, and no privileges are needed to exploit this flaw, though the attack complexity is rated High due to the requirement for a network-adjacent or on-path position. This vulnerability maps to CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (Siemens CERT, CISA ICS Advisory).
Successful exploitation allows an attacker to intercept and potentially modify TLS-encrypted communications between the IAM client and the authorization server, resulting in high confidentiality and integrity impact with no availability impact. Sensitive data such as authentication credentials, session tokens, and authorization responses could be captured or tampered with, potentially enabling unauthorized access to affected Siemens engineering environments. Given that the affected products are used in industrial design, plant engineering, and simulation contexts, credential compromise could facilitate further lateral movement into sensitive operational technology (OT) or engineering networks (Siemens CERT, CISA ICS Advisory).
Siemens has released patched versions for most affected products: NX V2412 (update to V2412.8700 or later), NX V2506 (update to V2506.6000 or later), Simcenter 3D (update to V2506.6000 or later), Simcenter Femap (update to V2506.0002 or later), Solid Edge SE2025 (update to V225.0 Update 10 or later), and Solid Edge SE2026 (update to V226.0 Update 1 or later). For COMOS V10.6, no patch was available at initial disclosure — users should consult Siemens for the latest guidance. As a general workaround, organizations should restrict network access to authorization servers, implement network segmentation to prevent unauthorized MitM positioning, and monitor for ARP spoofing or DNS manipulation on affected network segments (Siemens CERT, CISA ICS Advisory).
CISA published an ICS advisory (ICSA-25-345-04) on December 11, 2025, highlighting the vulnerability and recommending users apply Siemens patches and follow ICS security best practices (CISA ICS Advisory). A follow-up CISA advisory (ICSA-26-043-03) was published in February 2026, indicating continued tracking of the issue. Security news outlets including IT Security News and BeyondMachines covered the disclosure, noting that Siemens COMOS was affected by multiple flaws including at least one rated critical (BeyondMachines). Community reaction on social platforms was limited, consistent with the low EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."