CVE-2025-25267

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict the scope of files accessible to the simulation model. This could allow an unauthorized attacker to compromise the confidentiality of the system.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*

History

23 Sep 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*
First Time Siemens tecnomatix Plant Simulation
Siemens
Summary
  • (es) Se ha identificado una vulnerabilidad en Tecnomatix Plant Simulation V2302 (todas las versiones anteriores a V2302.0021) y Tecnomatix Plant Simulation V2404 (todas las versiones anteriores a V2404.0010). La aplicación afectada no restringe adecuadamente el alcance de los archivos a los que puede acceder el modelo de simulación. Esto podría permitir que un atacante no autorizado comprometa la confidencialidad del sistema.
References () https://cert-portal.siemens.com/productcert/html/ssa-507653.html - () https://cert-portal.siemens.com/productcert/html/ssa-507653.html - Vendor Advisory

11 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 10:15

Updated : 2025-09-23 15:24


NVD link : CVE-2025-25267

Mitre link : CVE-2025-25267

CVE.ORG link : CVE-2025-25267


JSON object : View

Products Affected

siemens

  • tecnomatix_plant_simulation
CWE
CWE-552

Files or Directories Accessible to External Parties