A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted WRL files.
An attacker could leverage this vulnerability to execute code in the context of the current process.
CVE ID: CVE-2025-23402
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor: Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product: Teamcenter Visualization V14.3, Teamcenter Visualization V2312, Teamcenter Visualization V2406, Teamcenter Visualization V2412, Tecnomatix Plant Simulation V2302, Tecnomatix Plant Simulation V2404
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 1.67% (scored less or equal to compared to others)
EPSS Date: 2025-04-09 (when was this score calculated)