CVE-2025-40744 HIGH

CVE-2025-40744

Vendor Siemens
Product Solid Edge SE2025
Weakness CWE-295
Published November 11, 2025
Last update November 12, 2025

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client certificates to connect to License Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks.

Key dates

02Disclosure timeline

November 11, 2025 CVE published
November 12, 2025 Record updated