CVE-2025-40801: Siemens Comos v10.6
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Affected products
- Siemens Comos v10.6: before V10.6.1 (fixed in V10.6.1)
- Siemens Jt BI-Directional Translator For Step: any version
- Siemens NX v2412: before V2412.8900 (fixed in V2412.8900)
- Siemens NX v2506: before V2506.6000 (fixed in V2506.6000)
- Siemens Simcenter 3d: before V2506.6000 (fixed in V2506.6000)
- Siemens Simcenter Femap: before V2506.0002 (fixed in V2506.0002)
- Siemens Simcenter Studio: before V2506.0001 (fixed in V2506.0001)
- Siemens Simcenter System Architect: before V2506.0001 (fixed in V2506.0001)
- Siemens Tecnomatix Plant Simulation: before V2504.0007 (fixed in V2504.0007)
Published 2025-12-09. Last modified 2026-10-07.