CVE-2025-40827
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | solid_edge | se2025 |
| siemens | software_center | <3.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a DLL hijacking issue in Siemens Software Center (all versions before V3.5) and Solid Edge SE2025 (all versions before V225.0 Update 10). An attacker can place a specially crafted DLL file on the system, which the affected application may load, allowing the attacker to execute arbitrary code.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to execute arbitrary code on your system with the privileges of the affected application. This can lead to unauthorized actions such as data theft, system compromise, or disruption of services.