Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in several engineering and design software products that could allow an attacker to intercept communications by impersonating a legitimate server. This is due to a failure to properly validate security certificates when establishing connections. The main concern is confirming whether these affected products are deployed in a way that could be targeted.
- Unchecked security certificates allow impersonation.
- Leadership should remember potential interception risks.
- Confirm relevance and exposure in your environment.
Attack Path
How an attacker could exploit the issue
An attacker could intercept communication between the IAM client and the authorization server by positioning themselves between the two. This is possible if the client is configured to connect to an authorization server over an untrusted network without proper server certificate validation.
- No authentication required.
- Man-in-the-middle attack.
- Compromised authorization process.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to intercept and potentially alter communications between the IAM client and the authorization server. This could impact the integrity of operations when the affected products are configured to use TLS for authorization and are vulnerable.
- Engineering software data integrity.
- Man-in-the-middle attacks.
- Compromised service authorization.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Siemens COMOS, NX, Simcenter, and Solid Edge products. The IAM client's failure to validate server certificates during TLS connections creates a man-in-the-middle risk. Ownership likely falls to teams managing engineering applications, potentially involving infrastructure and security teams for broader exposure and network-level controls. The first practical step is to inventory these Siemens products, assess their accessibility and criticality, identify the respective application owners, and then plan remediation based on risk.
- Identify affected Siemens applications.
- Verify product reachability and criticality.
- Coordinate with application owners for remediation.