ID

VAR-202503-0280


CVE

CVE-2025-23399


TITLE

Siemens'  Teamcenter Visualization  and  Tecnomatix Plant Simulation  Out-of-bounds read vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326

DESCRIPTION

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2025-23399 // JVNDB: JVNDB-2025-014326

AFFECTED PRODUCTS

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2312.0009

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2302.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2312.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.3.0.13

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2302.0021

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2412.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2404.0010

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2404.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2406.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2412.0002

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.0.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2406.0007

Trust: 1.0

vendor:シーメンスmodel:teamcenter visualizationscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:tecnomatix plant simulationscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326 // NVD: CVE-2025-23399

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-23399
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-014326
value: HIGH

Trust: 0.8

productcert@siemens.com: CVE-2025-23399
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-014326
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326 // NVD: CVE-2025-23399

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326 // NVD: CVE-2025-23399

EXTERNAL IDS

db:NVDid:CVE-2025-23399

Trust: 2.6

db:SIEMENSid:SSA-050438

Trust: 1.8

db:JVNid:JVNVU92252869

Trust: 0.8

db:ICS CERTid:ICSA-25-072-01

Trust: 0.8

db:JVNDBid:JVNDB-2025-014326

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326 // NVD: CVE-2025-23399

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-050438.html

Trust: 1.8

url:https://jvn.jp/vu/jvnvu92252869/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-23399

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-01

Trust: 0.8

sources: JVNDB: JVNDB-2025-014326 // NVD: CVE-2025-23399

SOURCES

db:JVNDBid:JVNDB-2025-014326
db:NVDid:CVE-2025-23399

LAST UPDATE DATE

2025-09-25T20:52:23.196000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2025-014326date:2025-09-24T05:56:00
db:NVDid:CVE-2025-23399date:2025-09-23T15:28:58.983

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2025-014326date:2025-09-24T00:00:00
db:NVDid:CVE-2025-23399date:2025-03-11T10:15:17.170