Improper certificate validation in Siemens Software Center and related Siemens applications

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-40745?

CVE-2025-40745 is a vulnerability classified as Improper Certificate Validation, affecting Siemens Software Center (affected versions: < V3.5.8.2), Simcenter 3D (affected versions: < V2506.6000), Simcenter Femap (affected versions: < V2506.0002), and 4 more products. This vulnerability is rated Medium, with a CVSS score of 6.3. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.

Affected products and scope

Siemens identifies the following products and version branches as affected:

  • Siemens Software Center: all versions less than V3.5.8.2.
  • Simcenter 3D: all versions less than V2506.6000.
  • Simcenter Femap: all versions less than V2506.0002.
  • Simcenter STAR-CCM+: all versions less than V2602.
  • Solid Edge SE2025: all versions less than V225.0 Update 13.
  • Solid Edge SE2026: all versions less than V226.0 Update 04.
  • Tecnomatix Plant Simulation: all versions less than V2504.0008.

The record does not provide a default status for versions outside these ranges. A parallel or unlisted branch should not be assumed to be unaffected.

Technical details

This is a CWE-295: Improper Certificate Validation flaw in the Siemens Analytics Toolkit that affects applications connecting to the Analytics Service endpoint. The affected applications do not properly validate client certificates, which can allow an inappropriate certificate to be accepted during a man-in-the-middle scenario. The scoring record describes network reachability, no required privileges, and no user interaction; it also includes an additional attack requirement that the available Siemens material does not explain. The exact certificate-checking logic, protocol details, and precise data that could be observed remain unknown from the available evidence.

Exploitability

The flaw can be reached remotely over the network by an unauthenticated attacker. The supplied scoring record requires no user interaction and describes low attack complexity, while also recording an additional attack requirement that Siemens does not explain in the advisory. The supplied record marks public exploit as false, but it does not establish the status of exploitation in the wild. No campaign, victim, or specific exploitation technique is identified.

Technical impact

The documented technical outcome is the potential for a man-in-the-middle attack against the application connection to the Analytics Service endpoint. The recorded impact is limited to confidentiality; the available data does not indicate an impact to integrity or availability. The attack can be performed remotely without authentication, but the record also includes an additional attack requirement that is not explained. Possible organisational consequences include having to assess the trustworthiness of data or sessions that traversed an intercepted connection, but no specific breach is established.

Business impact

The flaw could expose some data exchanged between an affected application and the Analytics Service endpoint when the connection is intercepted. This may undermine trust in the connection and create risk for operational or analytics data transmitted over that channel, although the specific data types are not identified. The available record does not indicate an impact to data integrity or service availability. Priority should be given to systems running an affected product whose Analytics Service connection crosses an untrusted or only partially trusted network.

Remediation

  1. Update each affected product to the corresponding Siemens remediation release:
  • Siemens Software Center to V3.5.8.2.
  • Simcenter 3D to V2506.6000.
  • Simcenter Femap to V2506.0002.
  • Simcenter STAR-CCM+ to V2602.
  • Solid Edge SE2025 to V225.0 Update 13.
  • Solid Edge SE2026 to V226.0 Update 04.
  • Tecnomatix Plant Simulation to V2504.0008.
  1. After updating, verify the installed version on every system and confirm that the application uses the remediation release for its product branch.
  2. Protect network access to the relevant systems with appropriate controls, and configure the environment according to Siemens Industrial Security guidance and product manuals.
  3. If immediate updating is not possible, apply the product-specific mitigation guidance in the Siemens advisory and restrict unnecessary connections to the Analytics Service endpoint. The available evidence does not describe a separate workaround beyond product-specific guidance and network protection.

Detection

  1. Inventory workstations and servers running Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, or Tecnomatix Plant Simulation.
  2. Record the installed version of each product and compare it with the affected boundaries in affected_summary. Version verification is the primary exposure check supported by the available evidence.
  3. Review application configuration and network paths used to connect to the Analytics Service endpoint, especially where traffic passes through a proxy or TLS inspection device.
  4. As a precaution, review proxy or TLS logs for unexpected certificate changes or validation failures. Siemens does not define a specific IOC or log event for this vulnerability, so generic monitoring is not a confirmed detection method.
  5. Check that network access protections and the Siemens operational security recommendations are applied. Absence of suspicious log evidence does not prove that a deployment is unaffected.
Sources (13)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan