CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-25266: A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All...

6.8 CVSS

Description

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict access to the file deletion functionality.
This could allow an unauthorized attacker to delete files even when access to the system should be prohibited, resulting in potential data loss or unauthorized modification of system files.

Classification

CVE ID: CVE-2025-25266

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.8

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Problem Types

CWE-552: Files or Directories Accessible to External Parties

Affected Products

Vendor: Siemens, Siemens

Product: Tecnomatix Plant Simulation V2302, Tecnomatix Plant Simulation V2404

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 2.79% (scored less or equal to compared to others)

EPSS Date: 2025-04-09 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-25266
https://cert-portal.siemens.com/productcert/html/ssa-507653.html

Timeline