VDB

ICSA-25-345-04

ICSA-25-345-04 PUBLISHED CVSS 7.400000095367432 HIGH

Multiple Siemens products are affected by improper certificate validation in IAM Client. This could allow an unauthenticated remote attacker to perform man in the middle attacks. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Solid Edge SE2025
COMOS V10.6
NX V2506
Simcenter 3D
NX V2412
Solid Edge SE2026
Simcenter Femap

Timeline

  • Dec 9, 2025 CVE Published
  • Mar 12, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›