ID

VAR-202503-0277


CVE

CVE-2025-23401


TITLE

Siemens'  Teamcenter Visualization  and  Tecnomatix Plant Simulation  Out-of-bounds read vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895

DESCRIPTION

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2025-23401 // JVNDB: JVNDB-2025-014895

AFFECTED PRODUCTS

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2312.0009

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2302.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2312.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2302.0021

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.3.0.13

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2412.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2404.0010

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2404.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2412.0002

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.0.0

Trust: 1.0

vendor:シーメンスmodel:tecnomatix plant simulationscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:teamcenter visualizationscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895 // NVD: CVE-2025-23401

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-23401
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-014895
value: HIGH

Trust: 0.8

productcert@siemens.com: CVE-2025-23401
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-014895
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895 // NVD: CVE-2025-23401

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895 // NVD: CVE-2025-23401

EXTERNAL IDS

db:NVDid:CVE-2025-23401

Trust: 2.6

db:SIEMENSid:SSA-050438

Trust: 1.8

db:ICS CERTid:ICSA-25-072-01

Trust: 0.8

db:JVNid:JVNVU92252869

Trust: 0.8

db:JVNDBid:JVNDB-2025-014895

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895 // NVD: CVE-2025-23401

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-050438.html

Trust: 1.8

url:https://jvn.jp/vu/jvnvu92252869/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-23401

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-01

Trust: 0.8

sources: JVNDB: JVNDB-2025-014895 // NVD: CVE-2025-23401

SOURCES

db:JVNDBid:JVNDB-2025-014895
db:NVDid:CVE-2025-23401

LAST UPDATE DATE

2025-10-03T21:00:13.327000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2025-014895date:2025-10-02T02:01:00
db:NVDid:CVE-2025-23401date:2025-09-23T15:28:41.053

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2025-014895date:2025-10-02T00:00:00
db:NVDid:CVE-2025-23401date:2025-03-11T10:15:17.510