Siemens Teamcenter 2412.x < 2412.0013 / 2506.x < 2506.0010 / 2512.x < 2512.2607 / 2606.x < 2606.2607 XSS (SSA-157465)

high Nessus Plugin ID 346900

Synopsis

An application installed on the remote host is affected by a cross-site scripting vulnerability.

Description

The version of Siemens Teamcenter installed on the remote host is 2412.x prior to 2412.0013, or 2506.x prior to 2506.0010, or 2512.x prior to 2512.2607, or 2606.x prior to 2606.2607. It is, therefore, affected by a reflected cross-site scripting vulnerability. Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Siemens Teamcenter version 2412.0013, 2506.0010, 2512.2607, 2606.2607, or later.

See Also

https://cert-portal.siemens.com/productcert/html/ssa-157465.html

Plugin Details

Severity: High

ID: 346900

File Name: siemens_teamcenter_ssa_157465.nasl

Version: 1.1

Type: Local

Agent: windows

Family: Misc.

Published: 9/17/2026

Updated: 9/17/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.91

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-58113

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v4

Risk Factor: High

Base Score: 8.5

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

CPE: cpe:/a:siemens:teamcenter

Required KB Items: installed_sw/Siemens Teamcenter

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-58113