CVE-2025-40744: Siemens Solid Edge SE2025

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client certificates to connect to License Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.

Affected products

  • Siemens Solid Edge SE2025: before V225.0 Update 11 (fixed in V225.0 Update 11)

Published 2025-11-11. Last modified 2026-06-17.