CVE-2025-40745 is an improper certificate validation vulnerability affecting multiple Siemens applications including Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025/SE2026, and Tecnomatix Plant Simulation. The flaw allows unauthenticated remote attackers to conduct man-in-the-middle (MITM) attacks by exploiting the applications' failure to properly validate client certificates when connecting to the Analytics Service endpoint. All versions below specific thresholds are vulnerable, with patched versions available for each product. The vulnerability carries a CVSS score of 3.7 (LOW) with a network-based attack vector that requires high attack complexity. The impact is limited to confidentiality, with no integrity or availability concerns. This suggests the attacker would need favorable network conditions and potentially specific timing or configuration to succeed, and any information disclosure would be minimal. There is no evidence of active exploitation in the wild. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) database and has no public exploit code availability. Community attention remains minimal, as reflected by the extremely low EPSS score of 0.00022, indicating this poses a lower risk compared to the broader CVE landscape. Organizations should apply available patches during routine maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2506.6000CPE matchmatch criteria | cpe:2.3:a:siemens:simcenter_3d:*:*:*:*:*:*:*:* | ||
< 2506.6000CPE matchmatch criteria | cpe:2.3:a:siemens:simcenter_femap:*:*:*:*:*:*:*:* | ||
< 2602CPE matchmatch criteria | cpe:2.3:a:siemens:simcenter_star-ccm\+_viewer:*:*:*:*:*:*:*:* | ||
< 3.5.8.2CPE matchmatch criteria | cpe:2.3:a:siemens:software_center:*:*:*:*:*:*:*:* | ||
< 225.0CPE matchmatch criteria | cpe:2.3:a:siemens:solid_edge_se2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.