External risk intelligence

IAM Client Missing Server Certificate Validation Allows Man-in-the-Middle Attacks

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-40800

The vulnerability involves missing server certificate validation within the IAM client of engineering and design software (COMOS, NX, Simcenter, Solid Edge). These products are typically used in isolated or internal corporate environments and are not commonly exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in several engineering and design software products that could allow an attacker to intercept communications by impersonating a legitimate server. This is due to a failure to properly validate security certificates when establishing connections. The main concern is confirming whether these affected products are deployed in a way that could be targeted.

  • Unchecked security certificates allow impersonation.
  • Leadership should remember potential interception risks.
  • Confirm relevance and exposure in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could intercept communication between the IAM client and the authorization server by positioning themselves between the two. This is possible if the client is configured to connect to an authorization server over an untrusted network without proper server certificate validation.

  • No authentication required.
  • Man-in-the-middle attack.
  • Compromised authorization process.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to intercept and potentially alter communications between the IAM client and the authorization server. This could impact the integrity of operations when the affected products are configured to use TLS for authorization and are vulnerable.

  • Engineering software data integrity.
  • Man-in-the-middle attacks.
  • Compromised service authorization.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Siemens COMOS, NX, Simcenter, and Solid Edge products. The IAM client's failure to validate server certificates during TLS connections creates a man-in-the-middle risk. Ownership likely falls to teams managing engineering applications, potentially involving infrastructure and security teams for broader exposure and network-level controls. The first practical step is to inventory these Siemens products, assess their accessibility and criticality, identify the respective application owners, and then plan remediation based on risk.

  • Identify affected Siemens applications.
  • Verify product reachability and criticality.
  • Coordinate with application owners for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2025-40800?

This vulnerability affects a range of Siemens engineering and design software, including COMOS, NX, Simcenter 3D, Simcenter Femap, and Solid Edge. These tools are specialized applications used by engineers and designers for complex product lifecycle management, simulation, and industrial system planning, requiring secure connections to identity and authorization servers to manage user access and permissions.

How does this vulnerability work?

The issue is categorized as CWE-295, which refers to improper certificate validation. In this case, the IAM client fails to verify the digital certificates presented by the authorization server during a TLS connection. Without this verification, the software cannot confirm it is talking to a legitimate server, creating a window for a man-in-the-middle attack where an attacker intercepts or tampers with the communication.

Does this vulnerability trigger automatically?

No, it does not trigger spontaneously. For this attack to occur, an adversary must successfully position themselves on the network path between the IAM client and the authorization server. The vulnerability is not triggered if the software is operating within a strictly controlled, trusted internal network where no malicious actor can intercept traffic.

Is my organization at risk from this vulnerability?

Halo Surface Signal indicates that risk is unlikely for most because these engineering tools are typically deployed within isolated or internal corporate environments, not directly on the public internet. You should evaluate if your specific deployment involves connections traversing untrusted networks or if your network architecture allows unauthorized parties to intercept local traffic.

What should I do if I use these Siemens products?

Begin by inventorying your systems to identify if you are running the specific versions of COMOS, NX, Simcenter, or Solid Edge mentioned in the advisory. Coordinate with your application owners to determine the network accessibility of these instances and prioritize applying the vendor-provided updates to correct the certificate validation process.

References