Post

Siemens Teamcenter Vulnerability Advisory

Siemens Teamcenter Vulnerability Advisory

Siemens Teamcenter Vulnerability Advisory

A reflected cross-site scripting vulnerability has been identified in the authentication redirect flow (/auth/) of Siemens Teamcenter. This vulnerability allows an unauthenticated remote attacker to inject JavaScript into an authenticated user’s session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim’s Teamcenter session. 🚨

Siemens has released new versions for the affected products and recommends updating to the latest versions. The following versions of Siemens Teamcenter are affected:

  • Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113)
  • Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113)
  • Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113)
  • Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113)

Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim’s Teamcenter session. The relevant CWE is CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’). Critical Infrastructure Sectors impacted include Critical Manufacturing and Information Technology, with deployments worldwide. 🌍

For remediation, Siemens advises updating to:

  • V2412.0013 or later version
  • V2506.0010 or later version
  • V2512.2607 or later version
  • V2606.2607 or later version

Enzo Alvarez from Bishop Fox reported this vulnerability to Siemens. The initial release date for this advisory was 2026-09-08.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Users should minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. They should also locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, more secure methods, such as Virtual Private Networks (VPNs), should be used, recognizing that VPNs may have vulnerabilities and should be updated to the most recent version available. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. 🔒

For more details, you can read the complete article here: Read full article\n

This post is licensed under CC BY 4.0 by the author.