CVE-2025-23363: Siemens Teamcenter
High severity, CVSS 7.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V14.3.0.14), Teamcenter V2312 (All versions < V2312.0010), Teamcenter V2406 (All versions < V2406.0008), Teamcenter V2412 (All versions < V2412.0004). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.
Affected products
- Siemens Teamcenter: from 14.3, before 14.3.0.14 (fixed in 14.3.0.14); from 2312.0, before 2312.0010 (fixed in 2312.0010); from 2406.0, before 2406.0008 (fixed in 2406.0008); from 2412.0, before 2412.0004 (fixed in 2412.0004); version 14.1 only; version 14.2 only
Published 2025-02-11. Last modified 2026-06-17.