Junglewise Threat Intelligence

CVE-2025-40745: Siemens Multiple Products improper certificate validation in Analytics Service

CVE-2025-40745 · Severity: low · CVSS 3.7 · Published 2026-04-14

Technologies: Siemens Simcenter Femap, Siemens Solid Edge Se2025. Vendors: Siemens.

Executive brief

Multiple Siemens industrial simulation and design applications are affected by a security flaw in how they verify digital certificates when connecting to analytics services. This vulnerability could allow an attacker to intercept or manipulate communications between the software and Siemens' servers, potentially exposing sensitive operational data. Affected products include popular engineering tools like Simcenter, Solid Edge, and Tecnomatix.

Technical details

A vulnerability (CWE-295) exists in the Siemens Analytics Toolkit used across several Siemens products. The affected applications do not properly validate client certificates when establishing a connection to the Analytics Service endpoint. An unauthenticated remote attacker positioned between the client and the service could exploit this to perform a man-in-the-middle (MitM) attack. This could lead to the disclosure of information transmitted to the analytics service. Siemens has released updates for all affected product lines to address this validation failure.

Affected products

  • Siemens Siemens Software Center < V3.5.8.2
  • Siemens Simcenter 3D < V2506.6000
  • Siemens Simcenter Femap < V2506.0002
  • Siemens Simcenter STAR-CCM+ < V2602
  • Siemens Solid Edge SE2025 < V225.0 Update 13
  • Siemens Solid Edge SE2026 < V226.0 Update 04
  • Siemens Tecnomatix Plant Simulation < V2504.0008

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: patched
  • 2026-04-14: advisory

References

Related threats