AI analysis
Siemens Teamcenter versions across the V2412, V2506, V2512, and V2606 releases fail to properly encode user-supplied input that is reflected into HTML attribute contexts in the authentication redirect flow served by the /auth/ endpoint. An unauthenticated remote attacker can craft a malicious URL; when an authenticated user loads it, arbitrary JavaScript executes in the user's browser within the victim's Teamcenter session. The attacker can then perform actions in Teamcenter as the victim, such as reading or modifying data accessible to that session. Any organization running one of the affected Teamcenter versions whose /auth/ endpoint is reachable by users is exposed, with risk concentrated on instances that are internet-facing or reachable by untrusted clients. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade affected installations to the fixed versions: Teamcenter V2412.0013, V2506.0010, V2512.2607, or V2606.2607, respectively. Until patched, limit who can reach the /auth/ endpoint (restrict to trusted networks or require VPN), and caution users against clicking links to Teamcenter URLs from untrusted sources. Check web server and proxy logs for requests to /auth/ containing unexpected parameters or script payloads as an indicator of probing.
Affected
| Siemens Teamcenter | V2412, all versions < V2412.0013 |
| Siemens Teamcenter | V2506, all versions < V2506.0010 |
| Siemens Teamcenter | V2512, all versions < V2512.2607 |
| Siemens Teamcenter | V2606, all versions < V2606.2607 |
Estimated exposure
largeplausibly on the order of 100k–1M enterprise users across tens of thousands of deployments (Teamcenter is Siemens' flagship PLM platform); the subset of /auth/… — Teamcenter is one of the most widely deployed enterprise PLM products in manufacturing, automotive and aerospace, so the user base is plausibly in the hundreds of thousands, though Teamcenter is typically deployed internally and only a…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.