CVE-2025-23402

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted WRL files. An attacker could leverage this vulnerability to execute code in the context of the current process.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*

History

23 Sep 2025, 15:28

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-050438.html - () https://cert-portal.siemens.com/productcert/html/ssa-050438.html - Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en Teamcenter Visualization V14.3 (todas las versiones &lt; V14.3.0.13), Teamcenter Visualization V2312 (todas las versiones &lt; V2312.0009), Teamcenter Visualization V2406 (todas las versiones &lt; V2406.0007), Teamcenter Visualization V2412 (todas las versiones &lt; V2412.0002), Tecnomatix Plant Simulation V2302 (todas las versiones &lt; V2302.0021), Tecnomatix Plant Simulation V2404 (todas las versiones &lt; V2404.0010). Las aplicaciones afectadas contienen una vulnerabilidad de uso posterior a la liberación que podría activarse al analizar archivos WRL especialmente manipulados. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual.
First Time Siemens tecnomatix Plant Simulation
Siemens teamcenter Visualization
Siemens
CPE cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*

11 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 10:15

Updated : 2025-09-23 15:28


NVD link : CVE-2025-23402

Mitre link : CVE-2025-23402

CVE.ORG link : CVE-2025-23402


JSON object : View

Products Affected

siemens

  • teamcenter_visualization
  • tecnomatix_plant_simulation
CWE
CWE-416

Use After Free