SSA-868571 PUBLISHED CVSS 7.400000095367432 HIGH

Multiple Siemens products are affected by improper certificate validation in IAM Client. This could allow an unauthenticated remote attacker to perform man in the middle attacks. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
NX V2412
COMOS V10.6
Solid Edge SE2026
NX V2506
Simcenter Femap
Simcenter 3D
Solid Edge SE2025

Timeline

References

Open in Interactive Console →