PT-2026-32606 · Siemens · Solid Edge Se2026+6
Published
2026-04-14
·
Updated
2026-04-23
·
CVE-2025-40745
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Siemens Software Center versions prior to V3.5.8.2
Simcenter 3D versions prior to V2506.6000
Simcenter Femap versions prior to V2506.0002
Simcenter STAR-CCM+ versions prior to V2602
Solid Edge SE2025 versions prior to V225.0 Update 13
Solid Edge SE2026 versions prior to V226.0 Update 04
Tecnomatix Plant Simulation versions prior to V2504.0008
Description
Applications do not properly validate client certificates when connecting to the 'Analytics Service' endpoint. This flaw allows an unauthenticated remote attacker to perform man-in-the-middle attacks, which occurs when an attacker intercepts and potentially alters communication between two parties.
Recommendations
Update Siemens Software Center to version V3.5.8.2 or later.
Update Simcenter 3D to version V2506.6000 or later.
Update Simcenter Femap to version V2506.0002 or later.
Update Simcenter STAR-CCM+ to version V2602 or later.
Update Solid Edge SE2025 to version V225.0 Update 13 or later.
Update Solid Edge SE2026 to version V226.0 Update 04 or later.
Update Tecnomatix Plant Simulation to version V2504.0008 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simcenter 3D
Simcenter Femap
Simcenter Star-Ccm+
Software Center
Solid Edge Se2025
Solid Edge Se2026
Tecnomatix Plant Simulation