CVE-2025-23396 Details
Description
A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.
A vulnerability allowing out-of-bounds write has been identified in multiple versions of Siemens Teamcenter Visualization and Tecnomatix Plant Simulation. This vulnerability arises when the applications parse specially crafted WRL files, potentially leading to memory corruption. An attacker could exploit this issue to execute code in the context of the current process.
Users are advised to update to the latest versions of the affected products. Specific update instructions can be found in the Siemens Security Advisory SSA-050438.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-050438.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens teamcenter visualization | >= 14.0.0, < 14.3.0.13 >= 2312.0, < 2312.0009 >= 2406.0, < 2406.0007 >= 2412.0, < 2412.0002 |
CPE
Remediation
| |
| siemens tecnomatix plant simulation | >= 2302.0, < 2302.0021 >= 2404.0, < 2404.0010 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |