ID

VAR-202505-1729


CVE

CVE-2025-32454


TITLE

Siemens'  Teamcenter Visualization  and  Tecnomatix Plant Simulation  Out-of-bounds read vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894

DESCRIPTION

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualization V2312 (All versions < V2312.0010), Teamcenter Visualization V2406 (All versions < V2406.0008), Teamcenter Visualization V2412 (All versions < V2412.0004), Tecnomatix Plant Simulation V2404 (All versions < V2404.0013). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2025-32454 // JVNDB: JVNDB-2025-014894

AFFECTED PRODUCTS

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2312.0010

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2406.008

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2312.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:ltversion:2404.0013

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2412.0

Trust: 1.0

vendor:siemensmodel:tecnomatix plant simulationscope:gteversion:2404.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:2406.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:2412.0004

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.3.0.14

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.3

Trust: 1.0

vendor:シーメンスmodel:tecnomatix plant simulationscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:teamcenter visualizationscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894 // NVD: CVE-2025-32454

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-32454
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-014894
value: HIGH

Trust: 0.8

productcert@siemens.com: CVE-2025-32454
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-014894
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894 // NVD: CVE-2025-32454

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894 // NVD: CVE-2025-32454

EXTERNAL IDS

db:NVDid:CVE-2025-32454

Trust: 2.6

db:SIEMENSid:SSA-486186

Trust: 1.8

db:SIEMENSid:SSA-542540

Trust: 1.8

db:JVNid:JVNVU92528757

Trust: 0.8

db:JVNid:JVNVU96443907

Trust: 0.8

db:ICS CERTid:ICSA-25-162-01

Trust: 0.8

db:ICS CERTid:ICSA-25-135-06

Trust: 0.8

db:JVNDBid:JVNDB-2025-014894

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894 // NVD: CVE-2025-32454

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-486186.html

Trust: 1.8

url:https://cert-portal.siemens.com/productcert/html/ssa-542540.html

Trust: 1.8

url:https://jvn.jp/vu/jvnvu92528757/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96443907/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-32454

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-06

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-01

Trust: 0.8

sources: JVNDB: JVNDB-2025-014894 // NVD: CVE-2025-32454

SOURCES

db:JVNDBid:JVNDB-2025-014894
db:NVDid:CVE-2025-32454

LAST UPDATE DATE

2025-10-03T19:44:45.827000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2025-014894date:2025-10-02T02:00:00
db:NVDid:CVE-2025-32454date:2025-09-23T15:26:08.277

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2025-014894date:2025-10-02T00:00:00
db:NVDid:CVE-2025-32454date:2025-05-13T10:15:24.953