CVE-2025-40744
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | solid_edge | 225.0_update_11 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Solid Edge SE2025 versions prior to V225.0 Update 11, where the application does not properly validate client certificates when connecting to the License Service endpoint. This flaw could allow an unauthenticated remote attacker to perform man-in-the-middle (MITM) attacks by intercepting or manipulating communications.
How can this vulnerability impact me? :
The vulnerability can allow an unauthenticated remote attacker to perform man-in-the-middle attacks, potentially intercepting or manipulating sensitive license service communications. This could lead to unauthorized access or disruption of licensing functionality, impacting software availability or security.