CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-25267: A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All...

6.2 CVSS

Description

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict the scope of files accessible to the simulation model. This could allow an unauthorized attacker to compromise the confidentiality of the system.

Classification

CVE ID: CVE-2025-25267

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.2

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem Types

CWE-552: Files or Directories Accessible to External Parties

Affected Products

Vendor: Siemens, Siemens

Product: Tecnomatix Plant Simulation V2302, Tecnomatix Plant Simulation V2404

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 1.88% (scored less or equal to compared to others)

EPSS Date: 2025-04-09 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-25267
https://cert-portal.siemens.com/productcert/html/ssa-507653.html

Timeline