External risk intelligence

SALT SDK TLS Validation Flaw Allows Man-in-the-Middle Attacks

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2025-40801

The vulnerability involves missing server certificate validation within the SALT SDK used by industrial engineering, simulation, and CAD software. These applications are typically deployed in internal, air-gapped, or segmented enterprise environments. While they may communicate with authorization servers, they are not standard public-facing internet services.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a vulnerability in several Siemens software products that could allow an attacker to intercept communications through a man-in-the-middle attack. The core issue is the failure to properly validate security certificates when connecting to an authorization server. While the affected software is typically used in controlled environments, the potential for intercepted communications warrants attention to confirm relevance and exposure.

  • The software fails to verify security certificates.
  • This allows attackers to intercept communications.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could intercept communications between affected software and its authorization server by exploiting a missing certificate validation in the SALT SDK. This man-in-the-middle attack allows the attacker to manipulate or eavesdrop on these sensitive communications.

  • Network access to the authorization server required.
  • Intercepting TLS connections to the authorization server.
  • Compromise of authentication and data integrity.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to intercept communication between affected software and its authorization server. This might happen when the software is configured to connect to an authorization server over TLS, and an attacker is able to position themselves in the communication path.

  • Design and simulation data could be exposed.
  • Man-in-the-middle attacks could occur.
  • Unauthorized access to software features may result.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Siemens software used in engineering and simulation, likely managed by product lifecycle management (PLM) or IT infrastructure teams. The first practical step is to identify all installations, confirm their reachability and criticality, and assign an owner for remediation planning.

  • Own by PLM or IT infrastructure teams.
  • Verify external reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2025-40801?

This vulnerability impacts various Siemens industrial engineering, CAD, and simulation tools including COMOS, NX, Simcenter, and Tecnomatix. These platforms are used by engineers to design, simulate, and manage complex industrial lifecycles. They rely on the SALT SDK to handle secure communications for licensing and authorization tasks.

How does this SALT SDK vulnerability work?

The software fails to perform proper server certificate validation during TLS connection establishment (CWE-295). Because the application does not verify the identity of the authorization server, it cannot confirm it is talking to a legitimate endpoint. This oversight allows an attacker to masquerade as the server, intercepting or modifying data meant for the official service.

What triggers a man-in-the-middle attack in this scenario?

An attack requires the malicious actor to position themselves in the network path between the affected software and its authorization server. The vulnerability does not trigger if the software is not actively attempting to initiate a TLS connection to an authorization server, or if the network path is fully trusted and isolated from unauthorized interception.

Is my organization at risk if these tools are internal?

According to Halo Surface Signal, this software is typically deployed in segmented or air-gapped enterprise environments rather than as public-facing services. While internet-facing instances increase risk, the primary concern is the ability of an attacker to access the specific internal network path used by the software to reach its authorization server.

What steps should I take if I run these products?

Coordinate with your PLM or IT infrastructure teams to create an inventory of all affected software versions within your environment. Verify which installations have network reachability to the authorization server and prioritize them for updates. Monitor vendor security portals for the latest patches to replace the vulnerable SALT SDK components.

References