
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40801 is an improper certificate validation vulnerability (CWE-295) in the SALT SDK used across multiple Siemens industrial and engineering software products. The flaw causes affected products to skip server certificate validation when establishing TLS connections to the authorization server, enabling man-in-the-middle (MITM) attacks. Affected products include COMOS V10.6 (all versions < V10.6.1), JT Bi-Directional Translator for STEP (all versions), NX V2412 (< V2412.8900), NX V2506 (< V2506.6000), Simcenter 3D (< V2506.6000), Simcenter Femap (< V2506.0002), Simcenter Studio (< V2506.0001), Simcenter System Architect (< V2506.0001), and Tecnomatix Plant Simulation (< V2504.0007). The vulnerability was published on December 9, 2025, and carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (Feedly, ENISA EUVD).
The root cause is CWE-295 (Improper Certificate Validation): the SALT SDK component, shared across multiple Siemens products, omits validation of the server's TLS certificate when connecting to the authorization server. This means the client will accept any certificate presented — including self-signed or attacker-controlled certificates — without verifying authenticity or chain of trust. An attacker positioned on the network path between the affected client and the authorization server (e.g., via ARP spoofing, DNS poisoning, or rogue access point) can intercept and manipulate the TLS session. No authentication or user interaction is required to exploit this flaw, though the attacker must be in a network position to intercept traffic (attack complexity is rated High under CVSSv3.1 due to this prerequisite) (Feedly, CISA ICS Advisory).
Successful exploitation allows an attacker to perform a MITM attack against the TLS channel between affected Siemens software and the authorization server, resulting in high impact to confidentiality, integrity, and availability. An attacker could intercept sensitive authentication tokens or credentials, modify authorization responses to escalate privileges or bypass licensing controls, and potentially disrupt access to cloud-entitlement-dependent features. Given that the affected products are used in industrial design, simulation, and plant operations environments, compromise could have downstream consequences for engineering workflows and operational technology (OT) environments (Feedly, ENISA EUVD).
Siemens has released patched versions for most affected products: NX V2412 → update to V2412.8900 or later; NX V2506 → V2506.6000 or later; Simcenter 3D → V2506.6000 or later; Simcenter Femap → V2506.0002 or later; Simcenter Studio → V2506.0001 or later; Simcenter System Architect → V2506.0001 or later; Tecnomatix Plant Simulation → V2504.0007 or later; COMOS V10.6 → V10.6.1 or later. JT Bi-Directional Translator for STEP has no fix available yet — Siemens recommends applying network segmentation and restricting network access to affected systems as interim mitigations. Organizations should also monitor network traffic for anomalous TLS activity and enforce network-level controls to prevent unauthorized MITM positioning (Siemens SSA-710408, CISA ICS Advisory).
CISA published ICS Advisory ICSA-25-345-05 on December 11, 2025, highlighting the vulnerability for industrial control system operators. Siemens disclosed the issue through two Product CERT advisories (SSA-710408 and SSA-212953). Coverage has been limited to automated vulnerability tracking platforms and ICS security news aggregators, with no notable independent researcher commentary or significant social media discussion identified (CISA ICS Advisory, Siemens SSA-710408).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."