ID

VAR-202503-0284


CVE

CVE-2025-27438


TITLE

Siemens'  Teamcenter Visualization  and  Tecnomatix Plant Simulation  Out-of-bounds read vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515

DESCRIPTION

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2025-27438 // JVNDB: JVNDB-2025-014515

AFFECTED PRODUCTS

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2312.0009

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2302.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2312.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.3.0.13

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2412.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:lteversion:2302.0021

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2404.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2404.0010

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2412.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2406.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2412.0002

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2412.0002

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2406.0007

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.3

Trust: 1.0

vendor:シーメンスmodel:tecnomatix plant simulationscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:teamcenter visualizationscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515 // NVD: CVE-2025-27438

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-27438
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-014515
value: HIGH

Trust: 0.8

productcert@siemens.com: CVE-2025-27438
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-014515
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515 // NVD: CVE-2025-27438

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515 // NVD: CVE-2025-27438

EXTERNAL IDS

db:NVDid:CVE-2025-27438

Trust: 2.6

db:SIEMENSid:SSA-050438

Trust: 1.8

db:JVNid:JVNVU92252869

Trust: 0.8

db:ICS CERTid:ICSA-25-072-01

Trust: 0.8

db:JVNDBid:JVNDB-2025-014515

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515 // NVD: CVE-2025-27438

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-050438.html

Trust: 1.8

url:https://jvn.jp/vu/jvnvu92252869/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-27438

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-01

Trust: 0.8

sources: JVNDB: JVNDB-2025-014515 // NVD: CVE-2025-27438

SOURCES

db:JVNDBid:JVNDB-2025-014515
db:NVDid:CVE-2025-27438

LAST UPDATE DATE

2025-09-27T23:45:37.899000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2025-014515date:2025-09-26T06:29:00
db:NVDid:CVE-2025-27438date:2025-09-23T15:24:03.457

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2025-014515date:2025-09-26T00:00:00
db:NVDid:CVE-2025-27438date:2025-03-11T10:15:19.407