CVE-2025-23396: Siemens Teamcenter Visualization
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.
Affected products
- Siemens Teamcenter Visualization: from 14.0.0, before 14.3.0.13 (fixed in 14.3.0.13); from 2312.0, before 2312.0009 (fixed in 2312.0009); from 2406.0, before 2406.0007 (fixed in 2406.0007); from 2412.0, before 2412.0002 (fixed in 2412.0002)
- Siemens Tecnomatix Plant Simulation: from 2302.0, before 2302.0021 (fixed in 2302.0021); from 2404.0, before 2404.0010 (fixed in 2404.0010)
Published 2025-03-11. Last modified 2026-06-17.