CVE-2025-40801
Siemens Tecnomatix Plant Simulation vulnerability analysis and mitigation

Overview

CVE-2025-40801 is an improper certificate validation vulnerability (CWE-295) in the SALT SDK used across multiple Siemens industrial and engineering software products. The flaw causes affected products to skip server certificate validation when establishing TLS connections to the authorization server, enabling man-in-the-middle (MITM) attacks. Affected products include COMOS V10.6 (all versions < V10.6.1), JT Bi-Directional Translator for STEP (all versions), NX V2412 (< V2412.8900), NX V2506 (< V2506.6000), Simcenter 3D (< V2506.6000), Simcenter Femap (< V2506.0002), Simcenter Studio (< V2506.0001), Simcenter System Architect (< V2506.0001), and Tecnomatix Plant Simulation (< V2504.0007). The vulnerability was published on December 9, 2025, and carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (Feedly, ENISA EUVD).

Technical details

The root cause is CWE-295 (Improper Certificate Validation): the SALT SDK component, shared across multiple Siemens products, omits validation of the server's TLS certificate when connecting to the authorization server. This means the client will accept any certificate presented — including self-signed or attacker-controlled certificates — without verifying authenticity or chain of trust. An attacker positioned on the network path between the affected client and the authorization server (e.g., via ARP spoofing, DNS poisoning, or rogue access point) can intercept and manipulate the TLS session. No authentication or user interaction is required to exploit this flaw, though the attacker must be in a network position to intercept traffic (attack complexity is rated High under CVSSv3.1 due to this prerequisite) (Feedly, CISA ICS Advisory).

Impact

Successful exploitation allows an attacker to perform a MITM attack against the TLS channel between affected Siemens software and the authorization server, resulting in high impact to confidentiality, integrity, and availability. An attacker could intercept sensitive authentication tokens or credentials, modify authorization responses to escalate privileges or bypass licensing controls, and potentially disrupt access to cloud-entitlement-dependent features. Given that the affected products are used in industrial design, simulation, and plant operations environments, compromise could have downstream consequences for engineering workflows and operational technology (OT) environments (Feedly, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify target environments running affected Siemens products (COMOS, NX, Simcenter, Tecnomatix) that use cloud entitlement/licensing features requiring TLS connections to an authorization server.
  2. Network Positioning: Gain a man-in-the-middle position on the network path between the target client and the Siemens authorization server — for example, via ARP spoofing on a local network segment, DNS poisoning, or deploying a rogue Wi-Fi access point.
  3. TLS Interception: Deploy a TLS interception proxy (e.g., mitmproxy, Burp Suite) configured with a self-signed or attacker-controlled certificate for the authorization server's hostname. Because the SALT SDK does not validate the server certificate, the client will complete the TLS handshake without error.
  4. Credential/Token Harvesting: Capture authentication tokens, OAuth credentials, or licensing data transmitted in the now-decrypted TLS session.
  5. Session Manipulation: Optionally modify authorization server responses in transit — for example, to alter license entitlements, inject malicious data, or deny service by returning invalid responses (CISA ICS Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected TLS connections from Siemens product hosts to IP addresses not associated with legitimate Siemens authorization servers; ARP table anomalies or duplicate MAC entries on network segments hosting affected systems; unusual DNS responses for Siemens authorization server hostnames resolving to unexpected IPs.
  • Logs: TLS handshake completions with certificates issued by unknown or self-signed certificate authorities in application or system TLS logs; authorization failures or unexpected license grant/denial events in Siemens product logs.
  • Process/Behavior: Siemens applications (NX, Simcenter, COMOS, Tecnomatix) exhibiting unexpected licensing errors or authentication failures that could indicate tampered authorization responses; repeated re-authentication attempts to the authorization server.

Mitigation and workarounds

Siemens has released patched versions for most affected products: NX V2412 → update to V2412.8900 or later; NX V2506 → V2506.6000 or later; Simcenter 3D → V2506.6000 or later; Simcenter Femap → V2506.0002 or later; Simcenter Studio → V2506.0001 or later; Simcenter System Architect → V2506.0001 or later; Tecnomatix Plant Simulation → V2504.0007 or later; COMOS V10.6 → V10.6.1 or later. JT Bi-Directional Translator for STEP has no fix available yet — Siemens recommends applying network segmentation and restricting network access to affected systems as interim mitigations. Organizations should also monitor network traffic for anomalous TLS activity and enforce network-level controls to prevent unauthorized MITM positioning (Siemens SSA-710408, CISA ICS Advisory).

Community reactions

CISA published ICS Advisory ICSA-25-345-05 on December 11, 2025, highlighting the vulnerability for industrial control system operators. Siemens disclosed the issue through two Product CERT advisories (SSA-710408 and SSA-212953). Coverage has been limited to automated vulnerability tracking platforms and ICS security news aggregators, with no notable independent researcher commentary or significant social media discussion identified (CISA ICS Advisory, Siemens SSA-710408).

Additional resources


SourceThis report was generated using AI

Related Siemens Tecnomatix Plant Simulation vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40801CRITICAL9.2
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesDec 09, 2025
CVE-2025-40945HIGH8.5
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesJul 14, 2026
CVE-2025-32454HIGH7.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesMay 13, 2025
CVE-2025-27438HIGH7.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesMar 11, 2025
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management