CVE-2025-23363 PUBLISHED CVSS 7.400000095367432 HIGH

A vulnerability has been identified in Teamcenter (All versions < V14.3.0.0). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.

EPSS 0.27% · 50.5th percentile

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS Score
0.27%
50.5th percentile

Affected Products

VendorProductVersions
SiemensTeamcenter V14.20
SiemensTeamcenter V14.10
SiemensTeamcenter V24120
SiemensTeamcenter V14.30
SiemensTeamcenter V23120
siemensteamcenter14.1, 14.2, 14.3
SiemensTeamcenter V24060

Timeline

References

Open in Interactive Console →