CVE-2025-40745: Siemens Simcenter 3d
Low severity, CVSS 3.7. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.
Affected products
- Siemens Simcenter 3d: before 2506.6000 (fixed in 2506.6000)
- Siemens Simcenter Femap: before 2506.6000 (fixed in 2506.6000)
- Siemens Simcenter Star-Ccm+ Viewer: before 2602 (fixed in 2602)
- Siemens Software Center: before 3.5.8.2 (fixed in 3.5.8.2)
- Siemens Solid Edge SE2025: before 225.0 (fixed in 225.0); version 225.0 only
- Siemens Solid Edge SE2026: before 226.0 (fixed in 226.0); version 226.0 only
- Siemens Tecnomatix Plant Simulation: before 2504.0008 (fixed in 2504.0008)
Published 2026-04-14. Last modified 2026-06-29.